Changeset 3426272
- Timestamp:
- 12/23/2025 02:35:01 PM (3 months ago)
- Location:
- wps-bidouille
- Files:
-
- 112 added
- 5 edited
-
tags/1.33.2 (added)
-
tags/1.33.2/admin_page (added)
-
tags/1.33.2/admin_page/plugin.php (added)
-
tags/1.33.2/admin_page/remove_from_cache.php (added)
-
tags/1.33.2/admin_page/suggest_plugins_themes.php (added)
-
tags/1.33.2/admin_page/suggestions.php (added)
-
tags/1.33.2/admin_page/tools.php (added)
-
tags/1.33.2/admin_page/white_label.php (added)
-
tags/1.33.2/assets (added)
-
tags/1.33.2/assets/css (added)
-
tags/1.33.2/assets/css/style.css (added)
-
tags/1.33.2/assets/fontawesome (added)
-
tags/1.33.2/assets/fontawesome/fontawesome-all.min.js (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/fontawesome-all.min.css (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-brands-400.eot (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-brands-400.svg (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-brands-400.ttf (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-brands-400.woff (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-brands-400.woff2 (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-light-300.eot (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-light-300.svg (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-light-300.ttf (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-light-300.woff (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-light-300.woff2 (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-regular-400.eot (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-regular-400.svg (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-regular-400.ttf (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-regular-400.woff (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-regular-400.woff2 (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-solid-900.eot (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-solid-900.svg (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-solid-900.ttf (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-solid-900.woff (added)
-
tags/1.33.2/assets/fontawesome/web-fonts-with-css/webfonts/fa-solid-900.woff2 (added)
-
tags/1.33.2/assets/img (added)
-
tags/1.33.2/assets/img/bg_pub.png (added)
-
tags/1.33.2/assets/img/bg_title_plugin.png (added)
-
tags/1.33.2/assets/img/check-and-tools-logo-in-plugin.png (added)
-
tags/1.33.2/assets/img/icone-encours.png (added)
-
tags/1.33.2/assets/js (added)
-
tags/1.33.2/assets/js/functions.js (added)
-
tags/1.33.2/assets/js/jquery (added)
-
tags/1.33.2/assets/js/jquery-tiptip (added)
-
tags/1.33.2/assets/js/jquery-tiptip/jquery.tipTip.js (added)
-
tags/1.33.2/assets/js/jquery-tiptip/jquery.tipTip.min.js (added)
-
tags/1.33.2/assets/js/jquery/jquery-migrate.min.js (added)
-
tags/1.33.2/assets/js/jquery/jquery.min.js (added)
-
tags/1.33.2/assets/js/notifs.js (added)
-
tags/1.33.2/autoload.php (added)
-
tags/1.33.2/blocks (added)
-
tags/1.33.2/blocks/check_cache.php (added)
-
tags/1.33.2/blocks/check_old_plugins.php (added)
-
tags/1.33.2/blocks/db_prefix.php (added)
-
tags/1.33.2/blocks/logs.php (added)
-
tags/1.33.2/blocks/menu.php (added)
-
tags/1.33.2/blocks/mysql.php (added)
-
tags/1.33.2/blocks/notifications.php (added)
-
tags/1.33.2/blocks/optimisations.php (added)
-
tags/1.33.2/blocks/pub.php (added)
-
tags/1.33.2/blocks/pub_wpboutik.php (added)
-
tags/1.33.2/blocks/report_system.php (added)
-
tags/1.33.2/blocks/server_information.php (added)
-
tags/1.33.2/blocks/settings_autoupdate.php (added)
-
tags/1.33.2/blocks/ssl.php (added)
-
tags/1.33.2/blocks/suggest (added)
-
tags/1.33.2/blocks/suggest/plugin_premiums.php (added)
-
tags/1.33.2/blocks/suggest/theme_premiums.php (added)
-
tags/1.33.2/blocks/suggest/themes.php (added)
-
tags/1.33.2/blocks/title.php (added)
-
tags/1.33.2/blocks/update_traduction.php (added)
-
tags/1.33.2/blocks/user_info.php (added)
-
tags/1.33.2/blocks/wpboutik.php (added)
-
tags/1.33.2/blocks/wps_cleaner.php (added)
-
tags/1.33.2/blocks/wps_hide_login.php (added)
-
tags/1.33.2/blocks/wps_limit_login.php (added)
-
tags/1.33.2/classes (added)
-
tags/1.33.2/classes/db-prefix.php (added)
-
tags/1.33.2/classes/disable-rest-api (added)
-
tags/1.33.2/classes/disable-rest-api/disable-rest-api.php (added)
-
tags/1.33.2/classes/helpers.php (added)
-
tags/1.33.2/classes/plugin.php (added)
-
tags/1.33.2/classes/removefromcache.php (added)
-
tags/1.33.2/classes/singleton.php (added)
-
tags/1.33.2/classes/suggest-plugins-themes.php (added)
-
tags/1.33.2/classes/suggestions.php (added)
-
tags/1.33.2/classes/systemreport.php (added)
-
tags/1.33.2/classes/tools.php (added)
-
tags/1.33.2/classes/whitelabel.php (added)
-
tags/1.33.2/composer.json (added)
-
tags/1.33.2/composer.lock (added)
-
tags/1.33.2/languages (added)
-
tags/1.33.2/languages/wps-bidouille-fr_FR.mo (added)
-
tags/1.33.2/languages/wps-bidouille-fr_FR.po (added)
-
tags/1.33.2/languages/wps-bidouille.pot (added)
-
tags/1.33.2/readme.txt (added)
-
tags/1.33.2/vendor (added)
-
tags/1.33.2/vendor/autoload.php (added)
-
tags/1.33.2/vendor/composer (added)
-
tags/1.33.2/vendor/composer/ClassLoader.php (added)
-
tags/1.33.2/vendor/composer/InstalledVersions.php (added)
-
tags/1.33.2/vendor/composer/LICENSE (added)
-
tags/1.33.2/vendor/composer/autoload_classmap.php (added)
-
tags/1.33.2/vendor/composer/autoload_namespaces.php (added)
-
tags/1.33.2/vendor/composer/autoload_psr4.php (added)
-
tags/1.33.2/vendor/composer/autoload_real.php (added)
-
tags/1.33.2/vendor/composer/autoload_static.php (added)
-
tags/1.33.2/vendor/composer/installed.json (added)
-
tags/1.33.2/vendor/composer/installed.php (added)
-
tags/1.33.2/vendor/composer/platform_check.php (added)
-
tags/1.33.2/wps-bidouille.php (added)
-
trunk/admin_page/plugin.php (modified) (1 diff)
-
trunk/assets/js/functions.js (modified) (3 diffs)
-
trunk/classes/plugin.php (modified) (3 diffs)
-
trunk/readme.txt (modified) (2 diffs)
-
trunk/wps-bidouille.php (modified) (2 diffs)
Legend:
- Unmodified
- Added
- Removed
-
wps-bidouille/trunk/admin_page/plugin.php
r3099121 r3426272 5 5 } ?> 6 6 7 <div id="plugin-filter" class="wrap" >7 <div id="plugin-filter" class="wrap" data-nonce="<?php echo wp_create_nonce('wps_bidouille_display'); ?>"> 8 8 <?php 9 9 include( WPS_BIDOUILLE_DIR . 'blocks/title.php' ); -
wps-bidouille/trunk/assets/js/functions.js
r2360339 r3426272 147 147 var h2 = $(this).parent().find('h2'); 148 148 var option_name = $(this).parent().attr('id'); 149 var nonce = $(this).parent().parent().parent().data('nonce'); 149 150 if (elem.hasClass('wps-hide')) { 150 151 elem.removeClass('wps-hide').addClass('wps-view'); … … 152 153 data = { 153 154 'action': 'delete_option_wps_display', 155 'wps-nonce': nonce, 154 156 'option_name': option_name 155 157 }; … … 162 164 data = { 163 165 'action': 'add_option_wps_display', 166 'wps-nonce': nonce, 164 167 'option_name': option_name 165 168 }; -
wps-bidouille/trunk/classes/plugin.php
r2659149 r3426272 214 214 'jquery', 215 215 'select2' 216 ), false, true );216 ), WPS_BIDOUILLE_VERSION, true ); 217 217 218 218 wp_localize_script( … … 393 393 394 394 public static function add_option_wps_display() { 395 if ( ! isset( $_POST['wps-nonce'] ) || ! wp_verify_nonce( $_POST['wps-nonce'], 'wps_bidouille_display' ) ) { 396 return false; 397 } 398 395 399 $option_name = sanitize_text_field( $_POST['option_name'] ); 396 400 if ( is_multisite() ) { … … 411 415 412 416 public static function delete_option_wps_display() { 417 if ( ! isset( $_POST['wps-nonce'] ) || ! wp_verify_nonce( $_POST['wps-nonce'], 'wps_bidouille_display' ) ) { 418 return false; 419 } 420 413 421 $option_name = sanitize_text_field( $_POST['option_name'] ); 414 422 if ( is_multisite() ) { -
wps-bidouille/trunk/readme.txt
r3316782 r3426272 5 5 Requires at least: 4.2 6 6 Tested up to: 6.8 7 Stable tag: 1.33. 17 Stable tag: 1.33.2 8 8 License: GPLv2 or later 9 9 License URI: http://www.gnu.org/licenses/gpl-2.0.html … … 132 132 == Changelog == 133 133 134 = 1.33.2 = 135 * Fix vulnerability (Thanks Legion Hunter - Patchstack) : Subscriber level user can inject any option field for option name "wps_display" via AJAX. 136 134 137 = 1.33.1 = 135 138 * Tested up to 6.8 -
wps-bidouille/trunk/wps-bidouille.php
r3316782 r3426272 6 6 Author: WPServeur, NicolasKulka, Benoti, wpformation 7 7 Author URI: https://wpserveur.net 8 Version: 1.33. 18 Version: 1.33.2 9 9 Requires at least: 4.2 10 10 Tested up to: 6.8 … … 21 21 22 22 // Plugin constants 23 define( 'WPS_BIDOUILLE_VERSION', '1.33. 1' );23 define( 'WPS_BIDOUILLE_VERSION', '1.33.2' ); 24 24 define( 'WPS_BIDOUILLE_FOLDER', 'wps-bidouille' ); 25 25 define( 'WPS_BIDOUILLE_BASENAME', plugin_basename( __FILE__ ) );
Note: See TracChangeset
for help on using the changeset viewer.