diff --git a/CHANGELOG.txt b/CHANGELOG.txt index 59e27b4e..da1fc325 100644 --- a/CHANGELOG.txt +++ b/CHANGELOG.txt @@ -1,4 +1,8 @@ == Changelog == += 7.0.10 - Oct 1, 2026 = +- Security improvements. Ecwid ecommerce shopping cart plugin update recommended. +- Verified compatibility with WordPress 7.1. + = 7.0.9 - Aug 8, 2026 = - **WordPress 7.0 compatibility.** The new WordPress version is released. The Ecwid ecommerce shopping cart plugin is ready for the new release — everything works well in your WordPress admin and storefront pages. Feel free to upgrade your site to WordPress 7.0. - **Plugin code improvements for better security. Ecwid ecommerce shopping cart plugin update recommended.** Thanks to Alexander Jurkschat for responsibly reporting the issue. @@ -1170,4 +1174,4 @@ We wish you happy holidays and all the best in the New Year! Sincerely yours, Ec - [!] Minor bugfixes = 0.1 = -- [+] Initial version of Ecwid Ecommerce Shopping Cart plugin \ No newline at end of file +- [+] Initial version of Ecwid Ecommerce Shopping Cart plugin diff --git a/includes/shortcodes/class-ecwid-shortcode-product.php b/includes/shortcodes/class-ecwid-shortcode-product.php index d4abf469..9e7ce7ca 100644 --- a/includes/shortcodes/class-ecwid-shortcode-product.php +++ b/includes/shortcodes/class-ecwid-shortcode-product.php @@ -76,11 +76,11 @@ public function render_placeholder() { foreach ( $items as $item ) { if ( array_key_exists( $item, $display_items ) ) { if ( $item == 'title' ) { - $display_items[ $item ] = str_replace( '$name', $product->name, $display_items[ $item ] ); + $display_items[ $item ] = str_replace( '$name', esc_attr( $product->name ), $display_items[ $item ] ); } if ( $item == 'price' ) { - $display_items[ $item ] = str_replace( '$price', $price, $display_items[ $item ] ); + $display_items[ $item ] = str_replace( '$price', esc_attr( $price ), $display_items[ $item ] ); } if ( $this->_params['link'] == 'yes' && in_array( $item, array( 'title', 'picture' ) ) ) { diff --git a/includes/widgets/class-ecwid-widget-random-product.php b/includes/widgets/class-ecwid-widget-random-product.php index 5a0c909b..c5bdf71c 100644 --- a/includes/widgets/class-ecwid-widget-random-product.php +++ b/includes/widgets/class-ecwid-widget-random-product.php @@ -20,22 +20,24 @@ protected function _render_widget_content( $args, $instance ) { } $name = esc_attr( $product->name ); - $url = $product->link; - $widget_id = 'ec-store-widget-random-' . $product->id; - - $content = "
-
-
-
- -
-
-
-
-
-
-
-
"; + $url = esc_url( $product->link ); + $price = esc_attr( $product->defaultDisplayedPrice ); + $product_id = absint( $product->id ); + $widget_id = 'ec-store-widget-random-' . $product_id; + + $content = "
+
+
+
+ +
+
+
+
+
+
+
+
"; $content .= Ec_Store_Defer_Init::print_js_widget( 'xProduct', $widget_id ); diff --git a/readme.txt b/readme.txt index e0297010..20dd133f 100644 --- a/readme.txt +++ b/readme.txt @@ -4,8 +4,8 @@ Tags: ecommerce, e-commerce, storefront, shopping cart, online store License: GPLv2 or later License URI: https://www.gnu.org/licenses/gpl-2.0.html Requires at least: 4.4 -Tested up to: 7.0 -Stable tag: 7.0.9 +Tested up to: 7.1 +Stable tag: 7.0.10 Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support. @@ -151,8 +151,12 @@ You can use Ecwid’s built-in import tools to copy your store products from any * [Ecwid Help Center](http://help.ecwid.com "Ecwid Help") -== Changelog == -= 7.0.9 - Aug 8, 2026 = +== Changelog == += 7.0.10 - Oct 1, 2026 = +- Security improvements. Ecwid ecommerce shopping cart plugin update recommended. +- Verified compatibility with WordPress 7.1. + += 7.0.9 - Aug 8, 2026 = - **WordPress 7.0 compatibility.** The new WordPress version is released. The Ecwid ecommerce shopping cart plugin is ready for the new release — everything works well in your WordPress admin and storefront pages. Feel free to upgrade your site to WordPress 7.0. - **Plugin code improvements for better security. Ecwid ecommerce shopping cart plugin update recommended.** Thanks to Alexander Jurkschat for responsibly reporting the issue. @@ -1323,4 +1327,4 @@ We wish you happy holidays and all the best in the New Year! Sincerely yours, Ec - [!] Minor bugfixes = 0.1 = -- [+] Initial version of Ecwid Ecommerce Shopping Cart plugin \ No newline at end of file +- [+] Initial version of Ecwid Ecommerce Shopping Cart plugin