Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
55 changes: 55 additions & 0 deletions wp-express-checkout/includes/class-utils.php
Original file line number Diff line number Diff line change
Expand Up @@ -793,6 +793,61 @@ public static function wpec_load_template( $template, $args = array(), $load_onc
return $tpl_html;
}

public static function wp_kses_common_attributes() {
$common_attributes = array(
'id' => true,
'class' => true,
'style' => true,
'title' => true,
'disabled' => true,
'aria-*' => true,
'data-*' => true,
);
return apply_filters( 'wpec_kses_common_attributes', $common_attributes );
}

public static function wp_kses_select_option_tags(){

$common_attributes = self::wp_kses_common_attributes();

$allowed_tags = array(
'option' => array_merge( $common_attributes, array(
'value' => true,
'label' => true,
'selected' => true,
) ),

'optgroup' => array_merge( $common_attributes, array(
'label' => true,
) ),
);

return apply_filters( 'wpec_kses_select_option_tags', $allowed_tags );
}

/**
* Returns allowed select field tags and attributes for wp_kses().
*
* @return array Allowed HTML tags and attributes.
*/
public static function wp_kses_select_tags() {
$allowed_tags = array(
'select' => array_merge( self::wp_kses_common_attributes(), array(
'name' => true,
'multiple' => true,
'required' => true,
'size' => true,
'form' => true,
'autocomplete' => true,
'autofocus' => true,
'tabindex' => true,
) ),
);
$allowed_tags = array_merge( $allowed_tags, self::wp_kses_select_option_tags() );

return apply_filters( 'wpec_kses_select_tags', $allowed_tags );
}

public static function wp_kses_post_tags_with_form() {
// Array of common standard and custom form attributes
$all_attributes = array(
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@

use WP_Express_Checkout\Debug\Logger;
use WP_Express_Checkout\Products;
use WP_Express_Checkout\Utils;

class Simple_WP_Membership extends Emember {

Expand Down Expand Up @@ -40,13 +41,13 @@ public function add_meta_boxes() {
public function display_meta_box( $post ) {
$current_val = get_post_meta( $post->ID, 'wpec_product_swpm_level', true );
?>
<p><?php esc_html_e( 'If you want this product to be connected to a membership level then select the membership Level here.', 'wp-express-checkout' ); ?></p>
<select name="wpec_product_swpm_level">
<option value=""><?php esc_html_e( 'None', 'wp-express-checkout' ); ?></option>
<?php
echo wp_kses_post( \SwpmUtils::membership_level_dropdown( $current_val ) );
?>
</select>
<p>
<?php esc_html_e( 'If you want this product to be connected to a membership level then select the membership Level here.', 'wp-express-checkout' ); ?>
</p>
<select name="wpec_product_swpm_level">
<option value=""><?php esc_html_e( 'None', 'wp-express-checkout' ); ?></option>
<?php echo wp_kses( \SwpmUtils::membership_level_dropdown( $current_val ), Utils::wp_kses_select_tags() ); ?>
</select>
<?php
}

Expand Down
2 changes: 2 additions & 0 deletions wp-express-checkout/readme.txt
Original file line number Diff line number Diff line change
Expand Up @@ -175,6 +175,8 @@ https://wp-express-checkout.com/
None

== Changelog ==
= WIP =
* Can't select membership level issue in product edit page has fixed.

= 2.5.2 =
* Improved the wpdb prepare statement in the function get_blog_ids().
Expand Down
Loading