diff --git a/includes/class-import-eventbrite-events-list-table.php b/includes/class-import-eventbrite-events-list-table.php index cab9ac0..8876044 100644 --- a/includes/class-import-eventbrite-events-list-table.php +++ b/includes/class-import-eventbrite-events-list-table.php @@ -61,12 +61,12 @@ function column_default( $item, $column_name ) { function column_title( $item ) { $iee_url_delete_args = array( - 'page' => wp_unslash( $_REQUEST['page'] ), + 'page' => esc_attr( wp_unslash( $_REQUEST['page'] ) ), 'iee_action' => 'iee_simport_delete', 'import_id' => absint( $item['ID'] ), ); - $page = wp_unslash( $_REQUEST['page'] ); + $page = esc_attr( wp_unslash( $_REQUEST['page'] ) ); $tab = 'scheduled'; $wp_redirect = admin_url( 'admin.php?page=' . $page ); $iee_url_edit_args = array( @@ -110,7 +110,7 @@ function column_title( $item ) { function column_action( $item ) { $xtmi_run_import_args = array( - 'page' => wp_unslash( $_REQUEST['page'] ), + 'page' => esc_attr( wp_unslash( $_REQUEST['page'] ) ), 'iee_action' => 'iee_run_import', 'import_id' => $item['ID'], ); @@ -435,8 +435,8 @@ function column_default( $item, $column_name ) { function column_title( $item ) { $iee_url_delete_args = array( - 'page' => wp_unslash( $_REQUEST['page'] ), - 'tab' => wp_unslash( $_REQUEST['tab'] ), + 'page' => esc_attr( wp_unslash( $_REQUEST['page'] ) ), + 'tab' => esc_attr( wp_unslash( $_REQUEST['tab'] ) ), 'iee_action' => 'iee_history_delete', 'history_id' => absint( $item['ID'] ), ); @@ -555,8 +555,8 @@ public function extra_tablenav( $which ) { return; } $iee_url_all_delete_args = array( - 'page' => wp_unslash( $_REQUEST['page'] ), - 'tab' => wp_unslash( $_REQUEST['tab'] ), + 'page' => esc_attr( wp_unslash( $_REQUEST['page'] ) ), + 'tab' => esc_attr( wp_unslash( $_REQUEST['tab'] ) ), 'iee_action' => 'iee_all_history_delete', ); diff --git a/languages/import-eventbrite-events.pot b/languages/import-eventbrite-events.pot index 82d2bf9..82fdf06 100644 --- a/languages/import-eventbrite-events.pot +++ b/languages/import-eventbrite-events.pot @@ -9,7 +9,7 @@ msgstr "" "MIME-Version: 1.0\n" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" -"POT-Creation-Date: 2024-11-30T07:42:52+00:00\n" +"POT-Creation-Date: 2024-12-13T06:31:15+00:00\n" "PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" "X-Generator: WP-CLI 2.11.0\n" "X-Domain: import-eventbrite-events\n" diff --git a/templates/admin/import-eventbrite-events-history.php b/templates/admin/import-eventbrite-events-history.php index cf225e8..301d357 100644 --- a/templates/admin/import-eventbrite-events-history.php +++ b/templates/admin/import-eventbrite-events-history.php @@ -13,8 +13,8 @@
- - + + display(); ?>