From e58beb120106eef13097a84291a2356af00532bc Mon Sep 17 00:00:00 2001 From: Savvas Hadjigeorgiou Date: Tue, 9 Nov 2021 08:24:23 +0200 Subject: [PATCH] Escaping vars from class-sp-ajax, class-sp-settings-status, class-sp-template-loader, class-sp-admin-dashboard and class-sp-widget-birthdays --- includes/admin/class-sp-admin-dashboard.php | 2 +- includes/admin/settings/class-sp-settings-status.php | 6 +++--- includes/class-sp-ajax.php | 6 +++--- includes/class-sp-template-loader.php | 2 +- includes/widgets/class-sp-widget-birthdays.php | 2 +- 5 files changed, 9 insertions(+), 9 deletions(-) diff --git a/includes/admin/class-sp-admin-dashboard.php b/includes/admin/class-sp-admin-dashboard.php index bafd2ddd..570ec260 100644 --- a/includes/admin/class-sp-admin-dashboard.php +++ b/includes/admin/class-sp-admin-dashboard.php @@ -54,7 +54,7 @@ class SP_Admin_Dashboard { else: $output = '' . $text . ''; endif; - echo '
  • ' . $output . '
  • '; + echo '
  • ' . esc_html( $output ) . '
  • '; endif; endforeach; return $items; diff --git a/includes/admin/settings/class-sp-settings-status.php b/includes/admin/settings/class-sp-settings-status.php index eae3cb45..d57028fd 100644 --- a/includes/admin/settings/class-sp-settings-status.php +++ b/includes/admin/settings/class-sp-settings-status.php @@ -245,7 +245,7 @@ class SP_Settings_Status extends SP_Settings_Page { if ( sizeof( $sp_plugins ) == 0 ) echo '-'; else - echo implode( ',
    ', $sp_plugins ); + echo implode( ',
    ', array_map( 'wp_kses_post', $sp_plugins ) ); ?> @@ -510,8 +510,8 @@ class SP_Settings_Status extends SP_Settings_Page { if ( $found_files ) { foreach ( $found_files as $plugin_name => $found_plugin_files ) { ?> - (): - ', $found_plugin_files ); ?> + (): + ', array_map( 'wp_kses_post', $found_plugin_files ) ); ?> $label ): ?> - +

    @@ -898,7 +898,7 @@ class SP_AJAX { $field_id = 'columns'; ?> - +

    @@ -1152,7 +1152,7 @@ class SP_AJAX { - +

    diff --git a/includes/class-sp-template-loader.php b/includes/class-sp-template-loader.php index 5778ec15..710180e4 100644 --- a/includes/class-sp-template-loader.php +++ b/includes/class-sp-template-loader.php @@ -78,7 +78,7 @@ class SP_Template_Loader { if ( 'yes' !== get_option( $template['option'], sp_array_value( $template, 'default', 'yes' ) ) ) continue; // Render the template - echo '

    '; + echo '
    '; if ( 'content' === $key ) { echo wp_kses_post( $content ); // Template content hook diff --git a/includes/widgets/class-sp-widget-birthdays.php b/includes/widgets/class-sp-widget-birthdays.php index 270cfe22..b656d055 100644 --- a/includes/widgets/class-sp-widget-birthdays.php +++ b/includes/widgets/class-sp-widget-birthdays.php @@ -77,7 +77,7 @@ class SP_Widget_Birthdays extends WP_Widget {