https://t.me/RX1948
Server : Apache
System : Linux s1230 5.15.0-139-generic #149~20.04.1 SMP Tue Jul 14 11:21:49 UTC 2026 x86_64
User : p141464 ( 418825)
PHP Version : 7.4.33.12
Disable Function : NONE
Directory :  /html/relaunch-kmu/wp-content/plugins/post-snippets/src/PostSnippets/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Current File : /html/relaunch-kmu/wp-content/plugins/post-snippets/src/PostSnippets/Shortcode.php
<?php
namespace PostSnippets;

/**
 * Shortcode Handling.
 *
 */
class Shortcode
{
    public function __construct()
    {
        $this->create();
    }

    /**
     * Create the functions for shortcodes dynamically and register them
     */
    public function create()
    {
        global $wpdb;

        $table_name = $wpdb->prefix . \PostSnippets::TABLE_NAME;

        $snippets = $wpdb->get_results($wpdb->prepare("SELECT * FROM $table_name WHERE snippet_shortcode = %d AND snippet_status = 1 AND snippet_content != ''", 1), ARRAY_A);

        foreach ($snippets as $snippet) {
            add_shortcode(
                $snippet['snippet_title'],
                function ($atts, $content = null) use ($snippet) {
                    return $this->evaluateSnippet($snippet, $atts, $content);
                }
            );
        }
    }

    public static function evaluateSnippet($snippet, $atts = array(), $content = null)
    {

        if (!empty($snippet)) {

            $default_atts = self::filterVars($snippet['snippet_vars']);

            $texturize = $snippet["snippet_wptexturize"] ?? false;

            $short_atts = shortcode_atts($default_atts, $atts);

            $snippet_content = $snippet['snippet_content'];

            if ($content != null) {
                $short_atts["content"] = $content;
            }

            // Check if PHP execution is enabled for this snippet
            $is_php_snippet = ($snippet['snippet_php'] == 1);

            // Security check: For PHP snippets, verify user has admin privileges BEFORE processing
            if ($is_php_snippet && !current_user_can('manage_options')) {
                return '<p><strong>' . esc_html__('Error: PHP snippet execution requires administrator privileges.', 'post-snippets') . '</strong></p>';
            }

            $scope_variables = array();

            // Prepare variables for scope injection logic
            foreach ($short_atts as $key => $val) {
                if ($is_php_snippet) {
                    // For PHP snippets, we DO NOT substitute the value directly.
                    // Instead, we assign the value to a unique variable and substitute the variable NAME.
                    // This prevents code injection because the user input is never parsed as code.

                    // Generate a safe variable name based on the key
                    // We use a prefix to ensure we don't overwrite any internal variables
                    $safe_key = 'attr_' . preg_replace('/[^a-zA-Z0-9_]/', '_', $key);

                    // Store the value in our scope array
                    $scope_variables[$safe_key] = $val;

                    // Replace {key} with $safe_key in the snippet content
                    // e.g. echo "{name}"; becomes echo "$attr_name";
                    $snippet_content = str_replace("{" . $key . "}", '$' . $safe_key, $snippet_content);

                } else {
                    // For non-PHP snippets, basic sanitization and standard substitution
                    $val = sanitize_text_field($val);
                    $snippet_content = str_replace("{" . $key . "}", $val, $snippet_content);
                }
            }

            // There might be the case that a snippet contains
            // the post snippets reserved variable {content} to
            // capture the content in enclosed shortcodes, but
            // the shortcode is used without enclosing it. To
            // avoid outputting {content} as part of the string
            // lets remove possible occurences.
            $snippet_content = str_replace("{content}", "", $snippet_content);

            // Handle PHP shortcodes
            if ($is_php_snippet) {

                // Extract the variables into the local scope so the eval'd code can access them
                // We pass them to phpEval now
                $snippet_content = self::phpEval($snippet_content, $scope_variables);

                // WPTexturize the Snippet
                if (!empty($snippet['snippet_wptexturize']) && ($snippet['snippet_wptexturize'] == true)) {

                    $snippet_content = html_entity_decode(addslashes(wptexturize(htmlentities(stripslashes($snippet_content), ENT_NOQUOTES))));

                }

            } else {

                if (!empty($snippet['snippet_wptexturize']) && ($snippet['snippet_wptexturize'] == true)) {

                    $snippet_content = html_entity_decode(addslashes(wptexturize(htmlentities(stripslashes($snippet_content), ENT_NOQUOTES))));
                } else {

                    $snippet_content = $snippet_content;
                }
            }

            $snippet_content = do_shortcode(stripslashes($snippet_content));

            return $snippet_content;
        }
    }

    /**
     * Evaluate a snippet as PHP code.
     *
     * @since   Post Snippets 1.9
     * @param   string  $content    The snippet to evaluate
     * @return  string              The result of the evaluation
     */
    public static function phpEval($content, $vars = array())
    {
        if (defined('POST_SNIPPETS_DISABLE_PHP')) {
            return $content;
        }

        $content = stripslashes($content);

        /**Removing Initial PHP Tag */
        $content = ltrim($content, "<?php<?PHP<?=");

        ob_start();
        if (!empty($vars)) {
            extract($vars);
        }
        eval ($content);
        $content = ob_get_clean();

        return addslashes($content);
    }



    /**
     * Filters Snippet Variables
     * of Undesired Text.
     *
     * @since   Post Snippets 3.1.4
     * @param   string  $vars       The snippet variable string
     * @return  array               The result of the evaluation
     */
    public static function filterVars($vars = '')
    {
        if (!empty($vars)) {

            $vars = explode(",", $vars);

            $default_atts = array();

            foreach ($vars as $var) {

                $attribute = explode('=', $var);        /**This Results in array seperated by = sign */

                foreach ($attribute as $key => $value) {    //Filtering Empty Values generated with such variable texts one,two=,,,=xx=one,,==two
                    if (empty($value))
                        unset($attribute[$key]);
                }

                if (empty($attribute))
                    continue;   /**After Unsetting Empty values above, any empty array still remains, so this line is skipping that */

                $attribute = array_values($attribute);      //resetting index to start with zero

                $default_value = (count($attribute) > 1) ? $attribute[1] : '';      /**Default values of vars, if set any */

                $default_atts[$attribute[0]] = $default_value;      /**Setting Default Atts for shortcode_atts  */

            }

            return $default_atts;
        } else {
            return array();
        }
    }
}

https://t.me/RX1948 - 2025