Plugin Directory

Changeset 3281953


Ignore:
Timestamp:
04/25/2025 02:22:19 PM (8 months ago)
Author:
shanebp
Message:

tagging 2.3

Location:
bp-messages-tool/tags/2.3
Files:
3 edited
1 copied

Legend:

Unmodified
Added
Removed
  • bp-messages-tool/tags/2.3/loader.php

    r2353122 r3281953  
    44Plugin URI: https://www.philopress.com
    55Description: View Messages for any BuddyPress member via wp-admin screen Tools > BP Messages
    6 Version: 2.2
     6Version: 2.3
    77Author: PhiloPress
    88Author URI: https://www.philopress.com/
  • bp-messages-tool/tags/2.3/readme.txt

    r2353122 r3281953  
    66Plugin URI: https://philopress.com/
    77Requires at least: WP 4.0
    8 Tested up to: 5.4
    9 Stable tag: 2.2
     8Tested up to: 6.8
     9Stable tag: 2.3
    1010License: GPLv2 or later
    1111
     
    4444
    4545== Changelog ==
     46
     47= 2.3 =
     48* fix XSS vulnerability
    4649
    4750= 2.2 =
  • bp-messages-tool/tags/2.3/templates/bpmt-messages-loop.php

    r2101672 r3281953  
    1212    $bpmt_get_member = '&user_id=' . $bpmt_user_data->ID;
    1313else
    14     $bpmt_get_member = '&user_id=' . $_GET['user'];
     14    $bpmt_get_member = '&user_id=' . intval( sanitize_text_field( $_GET['user'] ) );
    1515
    1616
    17 if( isset( $_GET['mpage'] ) )
    18     $bpmt_get_member .= '&mpage=' . $_GET['mpage'];
     17if( isset( $_GET['mpage'] ) ) {
     18   
     19    $mpage = intval( sanitize_text_field( $_GET['mpage'] ) );
     20   
     21    $bpmt_get_member .= '&mpage=' . $mpage;
     22   
     23}
    1924
    2025$bpmt_get_member .= '&box=' . $bpmt_user_data->box;
Note: See TracChangeset for help on using the changeset viewer.