PluginProbe
Contact Forms by Cimatti / 1.9.2
Contact Forms by Cimatti v1.9.2
2.3.6 2.3.5 2.3.0 2.2.32 2.2.4 2.2.0 2.1.2 2.1.1 trunk 1.0 1.1 1.2 1.2.1 1.3 1.3.1 1.3.2 1.3.3 1.3.4 1.3.5 1.3.6 1.3.7 1.3.8 1.3.9 1.4.0 1.4.1 All 62 releases
← All changes | readme.txt +184 -94 2.2.01.9.2 View file →
@@ -1,38 +1,23 @@
1 -=== Contact Forms by Cimatti ===
1 +=== WordPress Contact Forms by Cimatti ===
2 2 Contributors: cimatti
3 -Tags: contact form, form builder, email notifications, lead generation, form api
3 +Tags: contact, form, forms, contact form, contact forms, feedback, mail, email, ajax, attachment, curriculum, contact us, custom form, excel, form builder, web form, feedback, form manager, form to email, form to database, landing page, file upload, email form, customer request, spare parts, invitations, event forms, qtranslate, w3 total cache, drag and drop, form framework, form designer, form creator, php form builder
4 4 Requires at least: 3.5
5 -Tested up to: 7.0
6 -Stable tag: 2.2.0
7 -Requires PHP: 7.4
5 +Tested up to: 6.5.2
6 +Stable tag: 1.9.2
8 7 License: GPLv2 or later
9 8 License URI: http://www.gnu.org/licenses/gpl-2.0.html
10 9
11 -Create accessible contact forms with drag-and-drop. WCAG 2.2 compliant with screen reader support, keyboard navigation, and clear error messages.
10 +Create and publish forms in your WordPress website with drag and drop. Contact forms, landing page forms, invitations, and more.
12 11
13 12 == Description ==
14 -
15 -[**Live Preview - Try it in WordPress Playground**](https://wordpress.org/plugins/contact-forms/?preview=1) (form submission is not available in the live preview)
16 -
17 -Forms are an essential component of any website. Contact Forms by Cimatti is the culmination of years of experience building and developing business websites of all types. Our plugin focuses on simplicity, power, and **accessibility**, helping you capture, store, and classify contacts according to their lead status. It's ideal for single-language and multilingual sites, simple blogs, or complex WordPress-powered Content Management Systems.
18 -
19 -= Accessibility First =
20 -Contact Forms 2.0 is built with accessibility at its core, designed to meet **WCAG 2.2 AA** standards and comply with the **European Accessibility Act**:
21 -
22 -* **Screen Reader Support**: All form elements include proper ARIA labels, live regions for dynamic updates, and meaningful error announcements
23 -* **Keyboard Navigation**: Full keyboard accessibility for all interactions, including drag-and-drop file uploads
24 -* **Clear Error Messages**: Validation summary with clickable links to problematic fields, smooth scroll and focus management
25 -* **Accessible Loading States**: Visual and screen reader feedback during form submission
26 -* **Reduced Motion Support**: Respects `prefers-reduced-motion` user preference
27 -* **High Contrast**: Error and success states designed for visibility
28 -
13 +Forms are an essential component of any website. WordPress Contact Forms is the culmination of years of experience building and developing business websites of all types. Our plugin focuses on simplicity and power, it captures, stores and helps to classify contacts and leads according to their lead status. It's ideal for single-language and multilingual sites, simple blogs, or complex WordPress-powered Content Management Systems. If your website handles a considerable amount of contacts and you need to make diverse forms our plugin is an excellent choice.
29 14 = Select, Configure, and Embed Forms =
30 15 Choose the fields you require, customize on-screen messages and email responses, preview, test, and effortlessly embed forms into your posts, pages, or custom content types using shortcodes or the built-in TinyMCE button.
31 16 = Create Forms for Any Purpose =
32 17 Create as many forms as you need. Design landing pages, contact pages, invitations, job application forms with curriculum upload, customer request forms, spare part requests, and more. Utilize the "Clone" feature to avoid "reinventing the wheel" when creating new forms.
33 18 = Ready-to-Use Features =
34 -Contact Forms by Cimatti has commonly used fields like First Name, Last Name, Address, Province, Country, Telephone, Email, Captcha, and default success messages and email notifications. Simply create a drag-and-drop form, save it, go to a post or page, and click the orange "C" icon in the WYSIWYG editor to insert a contact form into the post or page content.
19 +WordPress Contact Forms has commonly used fields like First Name, Last Name, Address, Province, Country, Telephone, Email, Captcha, and default success messages and email notifications. Simply create a drag-and-drop form, save it, go to a post or page, and click the orange "C" icon in the WYSIWYG editor to insert a contact form into the post or page content.
35 20 = Easy to Use for Beginners =
36 21 These features make it effortless for first-time users, but the plugin's fast learning curve will soon entice you to explore its advanced features.
37 22 = Craft Superior Forms =
38 23 Don't leave anything to chance; fine-tune the entire form submission process.
@@ -49,27 +34,27 @@
49 34 All submitted data is securely stored in your WordPress database. Contacts received can be easily categorized into lead status categories and spam and tests can be easily discarded. Add notes on each contact received to keep track.
50 35
51 36 All contact data received can be filtered, searched, and exported to Excel at any time. You can export all the data or just the data you need. The Advanced Excel Export option allows you to export to a file with ready-to-use filtering options.
52 37
53 -Contact Forms also includes a tracking graph in its Dashboard that displays the performance of all or each of your website forms over time.
38 +WordPress Contact Forms also includes a tracking graph in its Dashboard that displays the performance of all or each of your website forms over time.
54 39
55 40 = Developer-Friendly API =
56 -Contact Forms by Cimatti includes an API to assist developers in customizing and adding their own features. WordPress Filters are used to customize forms during generation, to check and validate submitted form values, to execute custom code using sent data, and to add custom tokens for messages. Read the documentation on our site for more information.
41 +WordPress Contact Forms includes an API to assist developers in customizing and adding their own features. WordPress Filters are used to customize forms during generation, to check and validate submitted form values, to execute custom code using sent data, and to add custom tokens for messages. Read the documentation on our site for more information.
57 42 Powerful PHP Form Builder Class
58 -Contact Forms by Cimatti utilizes a PHP form builder class to generate the forms, ensuring robust and efficient form creation and management.
43 +WordPress Contact Forms utilizes a PHP form builder class to generate the forms, ensuring robust and efficient form creation and management.
59 44
60 45 == Installation ==
61 46 1. Upload `/contact-forms/` directory to the `/wp-content/plugins/` directory.
62 47 2. Activate the plugin through the 'Plugins' menu in WordPress.
63 48 3. Create one or more forms using the drag and drop interface.
64 -4. Edit posts (or pages or custom types) and add the desired form using the "C" button in the visual editor (or using the shortcode).
49 +4. Edit posts (or pages or custom types) and add the desired form using the "C" button in the visual editor (or using the shortcode.
65 50
66 51 == Frequently Asked Questions ==
67 -You'll find the [FAQ on our website](http://www.cimatti.it/en/wordpress-plugins/contact-forms/faq/).
52 +You'll find the [FAQ on our website](http://www.cimatti.it/wordpress/contact-forms/faq/).
68 53
69 54 = Where do I report security bugs found in this plugin? =
70 55 Please report security bugs found in the source code of the
71 -Contact Forms by Cimatti plugin through the [Patchstack
56 +WordPress Contact Forms by Cimatti plugin through the [Patchstack
72 57 Vulnerability Disclosure Program](https://patchstack.com/database/vdp/contact-forms). The
73 58 Patchstack team will assist you with verification, CVE assignment, and
74 59 notify the developers of this plugin.
75 60
@@ -84,86 +69,191 @@
84 69 8. Use screen options to show only the fields you need. Filter or search, then export.
85 70 9. Settings Page. Set up default options for all forms to avoid repetition.
86 71
87 72 == Changelog ==
73 += 1.9.2 =
74 +* Reverted an incorrect fix in the previous version
88 75
89 -= 2.2.0 =
90 -* Tested up to WordPress 7.0.
91 -* Added WordPress Playground blueprint for live preview on wordpress.org - five demo forms covering all field types including fieldsets, checkboxes, multi-select, post-select, and HTML blocks.
92 -* Email notifications: Long URLs no longer break print/PDF layout. Applied table-layout fixed and word-break on URL fields.
93 -* Email notifications: Improved vertical spacing between submitted fields with proper cell padding.
94 -* Email notifications: Fieldset labels now display correctly instead of raw field IDs.
95 -* Email notifications: Fixed malformed font-family quotes in the email body wrapper.
96 -* Single submission page: Restructured from 3-column to 2-column (30/70) layout. Details and Lead Status are now in the left column, submitted fields in the right.
97 -* Single submission page: Renamed "Stats" postbox to "Details".
98 -* Single submission page: Long URLs now wrap properly in the submitted fields table.
99 -* Submissions list: Added view links (Active, Trash, Lead Status) for quick filtering.
100 -* Submissions list: Refactored filter controls into native WP_List_Table extra_tablenav pattern.
101 -* Bugfix: Fieldset without a label no longer shows a gap in the border.
102 -* Bugfix: Essential Columns button race condition - column settings no longer lost during batch save.
103 -* Bugfix: Fields page - legacy-format fields now display correctly with proper name/slug fallback.
76 += 1.9.1 =
77 +* Hardening for potential SQL injection vulnerabilities
104 78
105 -= 2.1.4 =
106 -* Responsive sidebyside layout: labels automatically stack on top when the form container is narrower than 500px, using CSS container queries. Works across all themes regardless of viewport width.
79 += 1.9.0 =
80 +* Checks for unfiltered_html capability and supports limited admin permissions in WordPress multisite configurations
81 +* Filters the list of allowed upload file extensions according get_allowed_mime_types(), and check the maximum upload size with wp_max_upload_size()
82 +* Default date fix
83 +* Other minor fixes
107 84
108 -= 2.1.3 =
109 -* Fixed: Post select field value was not saved to database and not included in notification emails. The submission handler now resolves posts directly instead of relying on empty lazy-loaded options.
85 += 1.8.0 =
86 +* Using tinyColorPicker on frontend
87 +* Fixed XSS vulnerability
110 88
111 -= 2.1.2 =
112 -* Form editor: Added submission count with link to the submissions list, displayed inline with the page heading.
113 -* Form editor: Title input now has proper spacing and sizing matching WordPress core post editor styling.
114 -* Form editor: Google Ads and Tokens tabs now use WordPress postbox markup with form-table layout.
115 -* Form editor: Added unsaved changes warning (beforeunload prompt) when the form has been modified.
89 += 1.7.0 =
90 +* Lead status
91 +* Minor fixes
116 92
117 -= 2.1.1 =
118 -* Fixed single submission page: restored proper padding and spacing in the Lead status and Notes postbox
119 -* Improved layout alignment for Lead status dropdown and help icon
120 -* Italian: standardized terminology - "compilazione/compilazioni" for submissions, fixed mixed "modulo/moduli" back to "form/forms", translated all missing strings
121 -* Spanish: added ~260 missing translations (Theme Helper, Appearance, Danger Zone, default messages, block editor, GDPR)
93 += 1.6.1 =
94 +* Fixed trashed form restore
95 +* Fixed CSRF vulnerability
122 96
123 -= 2.1.0 =
124 -Admin UI modernization with a more coherent design language aligned with native WordPress admin patterns.
97 += 1.6.0 =
98 +* IP masking option
125 99
126 -* Flat single-level tab bar for the form editor (Fields, Appearance & General, Messages, Data Retention, Google Ads, Tokens)
127 -* Grid-based layout for form field editor and live preview
128 -* Tab navigation on the settings page with ARIA-compliant accessible tabs
129 -* Native WordPress postbox structure for all settings sections
130 -* Messages tab: 2×2 grid layout, accessible radio buttons with fieldset/label, TinyMCE font selector with 10 email-safe fonts
131 -* Default font changed from Lucida Sans to Arial for new forms
132 -* Merged dashboard.css into admin.css, removed dead CSS selectors
133 -* Bugfix: broken CSS selectors caused by panel ID renaming
134 -* Bugfix: Messages, Data Retention, and Tokens panels not properly contained within the tab system
100 += 1.5.10 =
101 +* Fixed plugin icon
135 102
136 -= 2.0.0 =
103 += 1.5.9 =
104 +* Fixed adding more custom HTML fields and fieldsets
137 105
138 -Major rewrite focused on accessibility, modern admin UI, and GDPR compliance. All existing forms continue to work without changes.
106 += 1.5.8 =
107 +* Fixed CSRF vulnerabilities
108 +* Fixed some JavaScript errors due to WordPress filters
109 +* Fixed many minor bugs
139 110
140 -**Important:** CSS changes (35 removed `!important` declarations) may affect frontend layouts customized via theme CSS. Use Contact Forms > Theme Helper to identify conflicts. Where possible, use the plugin's Appearance tab instead of theme CSS overrides.
111 += 1.5.7 =
112 +* tested compatibility with WordPress 6.2.0
141 113
142 -* Accessibility rewrite: WCAG 2.2 AA / European Accessibility Act compliance
143 -* Inline Labels layout (floating labels)
144 -* Live preview in the form editor
145 -* GDPR data retention, anonymization, and WordPress Privacy API
146 -* Cloudflare Turnstile support (via Simple Cloudflare Turnstile plugin)
147 -* Google reCAPTCHA v2 with built-in key configuration
148 -* Drag-and-drop file upload with keyboard navigation
149 -* Telephone field with E.164 validation and country prefix
150 -* Custom validation messages per field and per form
151 -* Custom CSS class and ID on all field types
152 -* Submissions list with sortable columns, row actions, and Excel export
153 -* Dashboard charts with monthly-by-page breakdown
154 -* Gutenberg block for inserting forms
155 -* Settings page with Danger Zone and deactivation cleanup
156 -* Theme Helper: diagnose CSS conflicts between your theme and Contact Forms
157 -* English, Italian, and Spanish translations
158 -* Plugin Check (PCP) fully compliant
114 += 1.5.6 =
115 +* Fixed CSRF vulnerability
159 116
160 -For the detailed per-beta changelog, see the plugin's changelog.txt file.
117 += 1.5.5 =
118 +* Fixed XSS vulnerabilities
161 119
162 -= 1.9.14 =
120 += 1.5.4 =
121 +* Graphical changes to default messages
122 +* Fixed some minor bugs
163 123
164 -* Added Cloudflare Turnstile field integration
124 += 1.5.3 =
125 +* Removed unused code
126 +* Fixed some minor issues
165 127
166 -== Upgrade Notice ==
128 += 1.5.2 =
129 +* Fixed critical error when trying to access the dashboard
167 130
168 -= 2.0.0 =
169 -Major rewrite: accessibility (WCAG 2.2 AA), GDPR tools, new layouts, spam protection, and modern admin UI. CSS changes may affect custom theme styling -- use Theme Helper to review. All existing forms continue to work.
131 += 1.5.1 =
132 +* Renewed UI
133 +* Fixing some minor bugs
134 +
135 += 1.4.14 =
136 +* Lazy load reCAPTCHA
137 +
138 += 1.4.13 =
139 +* added html attributes to improve SEO
140 +
141 += 1.4.12 =
142 +* Tested compatibility with PHP up to 8.0 and WordPress up to 5.8.1
143 +* reCAPTCHA loaded from recaptcha.net trying to improve accessibility from countries banning google.com domain
144 +* Fixed minor XSS vulnerability reported on wpscan.com by Felipe Restrepo Rodriguez and Sebastian Cruz Cardona. Form title was not sanitized in every place it was used in the admin interface, however this is mitigated by the fact that only admin users with manage_options capability can edit it.
145 +
146 += 1.4.11 =
147 +* avoid "headers already sent" warnings during WordPress cron
148 +
149 += 1.4.10 =
150 +* Tested compatibility with PHP up to 7.4
151 +* After submission, the fragment #formSubmitSuccess-formID is added to the URL, so the page is scrolled to the top of the message, and it's easier to track the submission with tools like Google Analytics
152 +* fragments #formSubmitInvalid-formID and #formSubmitError-formID are added in case of invalid submission or error
153 +* improved loading of reCAPTCHA
154 +* removed unused resources from PFBC library
155 +* colorPicker styles and javascripts now loads only if it's used
156 +* other small bugfixes
157 +
158 += 1.4.9 =
159 +* improved compatibility with Google Tag Manager to track field filled in and form submission
160 +
161 += 1.4.8 =
162 +* fixed compatibility issues with php 7.2
163 +* option to track field filled in and form submission as events on Google Analytics
164 +* workaround to open/download attachments in submissions exported and opened with Microsoft Excel
165 +
166 += 1.4.7 =
167 +* fixed compatibility issue with WordPress 4.8 that made show/hide buttons for field settings in the form editor invisible
168 +* fixed compatibility issues with php 7.0 and 7.1
169 +* fixed strict standards errors
170 +
171 += 1.4.6 =
172 +* restored compatibility with PHP < 5.3
173 +* fixed some strict standards errors
174 +
175 += 1.4.5 =
176 +* Scaled reCAPTCHA 2 area for devices with less than 400px screen width
177 +* More informations about senders and receivers of the form emails in the forms list page
178 +
179 += 1.4.4 =
180 +* Changed text domain of translatable strings to match the plugin slug
181 +* Bulk action to delete permanently trashed submissions
182 +
183 += 1.4.3 =
184 +* Fixed table index length issue that prevented saving submission values of new user of Contact Forms with recent WordPress versions
185 +* Added internationalization info
186 +
187 += 1.4.2 =
188 +* Fixed table definition error that prevented saving submission of new users of Contact Forms 1.4.0
189 +
190 += 1.4.1 =
191 +* Fixed undefined variable in accua-form-api.php on line 29
192 +
193 += 1.4.0 =
194 +* Filter and export by year and month
195 +* Added actions accua_forms_field_added, accua_forms_field_updated and accua_forms_field_deleted
196 +
197 += 1.3.9 =
198 +* better support for reCAPTCHA allowing to enter site keys and use version 2
199 +* fixed visualization bug of reCAPTCHA 1 with new WordPress themes
200 +* fixed bug that prevented editing fields on the page after a form submission
201 +
202 += 1.3.8 =
203 +* fixed incompatibility with WordPress 4.4 that prevented submissions export
204 +
205 += 1.3.7 =
206 +* fixed incompatibility with WordPress 4.4 that caused a PHP error in every page that includes a form
207 +* new token for select, checkbox and radio labels
208 +* changed database table to allow referrers and urls longer than 255 characters
209 +
210 += 1.3.6 =
211 +* Replaced deprecated user level '10' with capability 'manage_options'
212 +
213 += 1.3.5 =
214 +* fixed incompatibility of form editor with WordPress 4.3 and Chrome
215 +* adding rules to robots.txt to allow /wp-admin/js/ and /wp-admin/css/ for styles and scripts included from that folders
216 +
217 += 1.3.4 =
218 +* Password fields now saves the hash value of the password using wp_hash_password
219 +* Field to set the emails "From:" name
220 +* fixed CAPTCHA field incompatibility with CloudFlare RocketLoader and possibly other JavaScript optimizer
221 +* fixed glitch in the "Form fields" area on the "Edit form" page with latest versions of WordPress
222 +
223 += 1.3.3 =
224 +* improved checkboxes, select and radio definition to allow pre-selected options
225 +* fixed PHP 5.5 incompatibility issue. Now the plugin works with PHP from version 5.2 to 5.5
226 +* fixed default value for email, colorpicker and password fields
227 +* allowed removal of elements by a filter after the form generation
228 +
229 += 1.3.2 =
230 +* fixed visualization of color picker field
231 +* workaround to have multiple forms with recaptcha on the same page
232 +
233 += 1.3.1 =
234 +* fixed validation of required fields with multiple values
235 +* show recipient of admin email in form list
236 +* changes in submissions list generation and export to allow usage by other plugins
237 +
238 += 1.3 =
239 +* Spanish translation by Maria Ramos of [WebHostingHub](http://www.webhostinghub.com/)
240 +* Color picker field
241 +* Possibility to insert raw tokens in html messages
242 +* Disabled HTML5 validation of email fields, using JavaScript validation
243 +
244 += 1.2.1 =
245 +* Fixed installation and upgrade process issues introduced in 1.2
246 +* Users who installed 1.2 as their first version reported that submissions where not saved. Upgrading to this version will fix this issue
247 +
248 += 1.2 =
249 +* Fieldsets
250 +* Submissions trash and restore
251 +* Fixed counting of active and deleted forms
252 +* Fixed submission bug in Internet Explorer 8 and previous versions
253 +
254 += 1.1 =
255 +* Added interface to set basic form styles (borders, colors, padding)
256 +* Fixed captcha validation
257 +* Added submission graph by form
258 +* Screenshots removed from the package
259 +* Other minor fixes