@@ -110,8 +110,8 @@ public function find_category() {
110110 $ bookmark_mode = $ settings ->get_field ( 'bookmark_mode ' , 'cbxwpbookmark_basics ' , 'user_cat ' );
111111
112112
113- $ category_table = $ wpdb ->prefix . 'cbxwpbookmarkcat ' ;
114- $ bookmark_table = $ wpdb ->prefix . 'cbxwpbookmark ' ;
113+ $ category_table = esc_sql ( $ wpdb ->prefix . 'cbxwpbookmarkcat ' ) ;
114+ $ bookmark_table = esc_sql ( $ wpdb ->prefix . 'cbxwpbookmark ' ) ;
115115
116116 $ user_id = absint ( get_current_user_id () ); //get the current logged in user id
117117 $ object_id = isset ( $ _POST ['object_id ' ] ) ? absint ( $ _POST ['object_id ' ] ) : 0 ;
@@ -558,8 +558,8 @@ public function add_category() {
558558 check_ajax_referer ( 'cbxbookmarknonce ' , 'security ' );
559559
560560 global $ wpdb ;
561- $ category_table = $ wpdb ->prefix . 'cbxwpbookmarkcat ' ;
562- $ bookmark_table = $ wpdb ->prefix . 'cbxwpbookmark ' ;
561+ $ category_table = esc_sql ( $ wpdb ->prefix . 'cbxwpbookmarkcat ' ) ;
562+ $ bookmark_table = esc_sql ( $ wpdb ->prefix . 'cbxwpbookmark ' ) ;
563563
564564 $ cat_id = isset ( $ _POST ['cat_id ' ] ) ? intval ( $ _POST ['cat_id ' ] ) : 0 ;
565565 $ cat_name = isset ( $ _POST ['cat_name ' ] ) ? sanitize_text_field ( wp_unslash ( $ _POST ['cat_name ' ] ) ) : '' ;
@@ -688,8 +688,8 @@ public function edit_category() {
688688 check_ajax_referer ( 'cbxbookmarknonce ' , 'security ' );
689689
690690 global $ wpdb ;
691- $ category_table = $ wpdb ->prefix . 'cbxwpbookmarkcat ' ;
692- $ bookmark_table = $ wpdb ->prefix . 'cbxwpbookmark ' ;
691+ $ category_table = esc_sql ( $ wpdb ->prefix . 'cbxwpbookmarkcat ' ) ;
692+ $ bookmark_table = esc_sql ( $ wpdb ->prefix . 'cbxwpbookmark ' ) ;
693693
694694
695695 $ cat_id = isset ( $ _POST ['cat_id ' ] ) ? intval ( $ _POST ['cat_id ' ] ) : 0 ;
@@ -804,7 +804,7 @@ public function update_bookmark_category() {
804804 $ user_id = get_current_user_id ();
805805
806806 // Category Table with database Prefix
807- $ category_table = $ wpdb ->prefix . 'cbxwpbookmarkcat ' ;
807+ $ category_table = esc_sql ( $ wpdb ->prefix . 'cbxwpbookmarkcat ' ) ;
808808
809809 // Update Query
810810 // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
@@ -862,8 +862,8 @@ public function delete_bookmark_category() {
862862 $ cat_id = isset ( $ _POST ['id ' ] ) ? absint ( $ _POST ['id ' ] ) : 0 ;
863863
864864
865- $ category_table = $ wpdb ->prefix . 'cbxwpbookmarkcat ' ;
866- $ bookmark_table = $ wpdb ->prefix . 'cbxwpbookmark ' ;
865+ $ category_table = esc_sql ( $ wpdb ->prefix . 'cbxwpbookmarkcat ' ) ;
866+ $ bookmark_table = esc_sql ( $ wpdb ->prefix . 'cbxwpbookmark ' ) ;
867867
868868 $ user_id = get_current_user_id ();
869869
@@ -967,7 +967,7 @@ public function add_bookmark() {
967967
968968 $ object_type = isset ( $ _POST ['object_type ' ] ) ? sanitize_text_field ( wp_unslash ( $ _POST ['object_type ' ] ) ) : 'post ' ; //post, page or any custom post and later any object type
969969
970- $ bookmark_table = $ wpdb ->prefix . 'cbxwpbookmark ' ;
970+ $ bookmark_table = esc_sql ( $ wpdb ->prefix . 'cbxwpbookmark ' ) ;
971971 $ user_bookmarks_count = cbxwpbookmarks_getTotalBookmarkByUser ( $ user_id );
972972 $ category_privacy = 1 ;
973973
@@ -1107,7 +1107,6 @@ public function delete_bookmark_post() {
11071107 $ object_type = isset ( $ _POST ['object_type ' ] ) ? sanitize_text_field ( wp_unslash ( $ _POST ['object_type ' ] ) ) : 'post ' ; //post, page or any custom post and later any object type
11081108
11091109
1110- //$bookmark_table = $wpdb->prefix . 'cbxwpbookmark';
11111110
11121111 $ user_id = get_current_user_id ();
11131112
@@ -1298,8 +1297,8 @@ public function load_bookmarks_sublist() {
12981297 $ bookmark_mode = $ settings ->get_field ( 'bookmark_mode ' , 'cbxwpbookmark_basics ' , 'user_cat ' );
12991298
13001299
1301- $ category_table = $ wpdb ->prefix . 'cbxwpbookmarkcat ' ;
1302- $ bookmark_table = $ wpdb ->prefix . 'cbxwpbookmark ' ;
1300+ $ category_table = esc_sql ( $ wpdb ->prefix . 'cbxwpbookmarkcat ' ) ;
1301+ $ bookmark_table = esc_sql ( $ wpdb ->prefix . 'cbxwpbookmark ' ) ;
13031302
13041303 $ user_id = absint ( get_current_user_id () ); //get the current logged in user id
13051304
@@ -1530,7 +1529,7 @@ public function delete_all_bookmarks_by_user() {
15301529
15311530 if ( is_array ( $ bookmarks ) && sizeof ( $ bookmarks ) > 0 ) {
15321531 global $ wpdb ;
1533- $ bookmark_table = $ wpdb ->prefix . 'cbxwpbookmark ' ;
1532+ $ bookmark_table = esc_sql ( $ wpdb ->prefix . 'cbxwpbookmark ' ) ;
15341533
15351534 foreach ( $ bookmarks as $ single_bookmark ) {
15361535 $ id = absint ( $ single_bookmark ['id ' ] );
0 commit comments