PluginProbe
Contact Forms by Cimatti / 1.9.2
Contact Forms by Cimatti v1.9.2
2.3.6 2.3.5 2.3.0 2.2.32 2.2.4 2.2.0 2.1.2 2.1.1 trunk 1.0 1.1 1.2 1.2.1 1.3 1.3.1 1.3.2 1.3.3 1.3.4 1.3.5 1.3.6 1.3.7 1.3.8 1.3.9 1.4.0 1.4.1 All 62 releases
← All changes | readme.txt +180 -114 2.2.41.9.2 View file →
@@ -1,38 +1,23 @@
1 -=== Contact Forms by Cimatti ===
1 +=== WordPress Contact Forms by Cimatti ===
2 2 Contributors: cimatti
3 -Tags: contact form, form builder, email notifications, lead generation, form api
3 +Tags: contact, form, forms, contact form, contact forms, feedback, mail, email, ajax, attachment, curriculum, contact us, custom form, excel, form builder, web form, feedback, form manager, form to email, form to database, landing page, file upload, email form, customer request, spare parts, invitations, event forms, qtranslate, w3 total cache, drag and drop, form framework, form designer, form creator, php form builder
4 4 Requires at least: 3.5
5 -Tested up to: 7.0
6 -Stable tag: 2.2.4
7 -Requires PHP: 7.4
5 +Tested up to: 6.5.2
6 +Stable tag: 1.9.2
8 7 License: GPLv2 or later
9 8 License URI: http://www.gnu.org/licenses/gpl-2.0.html
10 9
11 -Create accessible contact forms with drag-and-drop. WCAG 2.2 compliant with screen reader support, keyboard navigation, and clear error messages.
10 +Create and publish forms in your WordPress website with drag and drop. Contact forms, landing page forms, invitations, and more.
12 11
13 12 == Description ==
14 -
15 -[**Live Preview - Try it in WordPress Playground**](https://wordpress.org/plugins/contact-forms/?preview=1) (form submission is not available in the live preview)
16 -
17 -Forms are an essential component of any website. Contact Forms by Cimatti is the culmination of years of experience building and developing business websites of all types. Our plugin focuses on simplicity, power, and **accessibility**, helping you capture, store, and classify contacts according to their lead status. It's ideal for single-language and multilingual sites, simple blogs, or complex WordPress-powered Content Management Systems.
18 -
19 -= Accessibility First =
20 -Contact Forms 2.0 is built with accessibility at its core, designed to meet **WCAG 2.2 AA** standards and comply with the **European Accessibility Act**:
21 -
22 -* **Screen Reader Support**: All form elements include proper ARIA labels, live regions for dynamic updates, and meaningful error announcements
23 -* **Keyboard Navigation**: Full keyboard accessibility for all interactions, including drag-and-drop file uploads
24 -* **Clear Error Messages**: Validation summary with clickable links to problematic fields, smooth scroll and focus management
25 -* **Accessible Loading States**: Visual and screen reader feedback during form submission
26 -* **Reduced Motion Support**: Respects `prefers-reduced-motion` user preference
27 -* **High Contrast**: Error and success states designed for visibility
28 -
13 +Forms are an essential component of any website. WordPress Contact Forms is the culmination of years of experience building and developing business websites of all types. Our plugin focuses on simplicity and power, it captures, stores and helps to classify contacts and leads according to their lead status. It's ideal for single-language and multilingual sites, simple blogs, or complex WordPress-powered Content Management Systems. If your website handles a considerable amount of contacts and you need to make diverse forms our plugin is an excellent choice.
29 14 = Select, Configure, and Embed Forms =
30 15 Choose the fields you require, customize on-screen messages and email responses, preview, test, and effortlessly embed forms into your posts, pages, or custom content types using shortcodes or the built-in TinyMCE button.
31 16 = Create Forms for Any Purpose =
32 17 Create as many forms as you need. Design landing pages, contact pages, invitations, job application forms with curriculum upload, customer request forms, spare part requests, and more. Utilize the "Clone" feature to avoid "reinventing the wheel" when creating new forms.
33 18 = Ready-to-Use Features =
34 -Contact Forms by Cimatti has commonly used fields like First Name, Last Name, Address, Province, Country, Telephone, Email, Captcha, and default success messages and email notifications. Simply create a drag-and-drop form, save it, go to a post or page, and click the orange "C" icon in the WYSIWYG editor to insert a contact form into the post or page content.
19 +WordPress Contact Forms has commonly used fields like First Name, Last Name, Address, Province, Country, Telephone, Email, Captcha, and default success messages and email notifications. Simply create a drag-and-drop form, save it, go to a post or page, and click the orange "C" icon in the WYSIWYG editor to insert a contact form into the post or page content.
35 20 = Easy to Use for Beginners =
36 21 These features make it effortless for first-time users, but the plugin's fast learning curve will soon entice you to explore its advanced features.
37 22 = Craft Superior Forms =
38 23 Don't leave anything to chance; fine-tune the entire form submission process.
@@ -49,27 +34,27 @@
49 34 All submitted data is securely stored in your WordPress database. Contacts received can be easily categorized into lead status categories and spam and tests can be easily discarded. Add notes on each contact received to keep track.
50 35
51 36 All contact data received can be filtered, searched, and exported to Excel at any time. You can export all the data or just the data you need. The Advanced Excel Export option allows you to export to a file with ready-to-use filtering options.
52 37
53 -Contact Forms also includes a tracking graph in its Dashboard that displays the performance of all or each of your website forms over time.
38 +WordPress Contact Forms also includes a tracking graph in its Dashboard that displays the performance of all or each of your website forms over time.
54 39
55 40 = Developer-Friendly API =
56 -Contact Forms by Cimatti includes an API to assist developers in customizing and adding their own features. WordPress Filters are used to customize forms during generation, to check and validate submitted form values, to execute custom code using sent data, and to add custom tokens for messages. Read the documentation on our site for more information.
41 +WordPress Contact Forms includes an API to assist developers in customizing and adding their own features. WordPress Filters are used to customize forms during generation, to check and validate submitted form values, to execute custom code using sent data, and to add custom tokens for messages. Read the documentation on our site for more information.
57 42 Powerful PHP Form Builder Class
58 -Contact Forms by Cimatti utilizes a PHP form builder class to generate the forms, ensuring robust and efficient form creation and management.
43 +WordPress Contact Forms utilizes a PHP form builder class to generate the forms, ensuring robust and efficient form creation and management.
59 44
60 45 == Installation ==
61 46 1. Upload `/contact-forms/` directory to the `/wp-content/plugins/` directory.
62 47 2. Activate the plugin through the 'Plugins' menu in WordPress.
63 48 3. Create one or more forms using the drag and drop interface.
64 -4. Edit posts (or pages or custom types) and add the desired form using the "C" button in the visual editor (or using the shortcode).
49 +4. Edit posts (or pages or custom types) and add the desired form using the "C" button in the visual editor (or using the shortcode.
65 50
66 51 == Frequently Asked Questions ==
67 -You'll find the [FAQ on our website](http://www.cimatti.it/en/wordpress-plugins/contact-forms/faq/).
52 +You'll find the [FAQ on our website](http://www.cimatti.it/wordpress/contact-forms/faq/).
68 53
69 54 = Where do I report security bugs found in this plugin? =
70 55 Please report security bugs found in the source code of the
71 -Contact Forms by Cimatti plugin through the [Patchstack
56 +WordPress Contact Forms by Cimatti plugin through the [Patchstack
72 57 Vulnerability Disclosure Program](https://patchstack.com/database/vdp/contact-forms). The
73 58 Patchstack team will assist you with verification, CVE assignment, and
74 59 notify the developers of this plugin.
75 60
@@ -84,110 +69,191 @@
84 69 8. Use screen options to show only the fields you need. Filter or search, then export.
85 70 9. Settings Page. Set up default options for all forms to avoid repetition.
86 71
87 72 == Changelog ==
73 += 1.9.2 =
74 +* Reverted an incorrect fix in the previous version
88 75
89 -= 2.2.4 =
90 -* Form editor: Appearance tab labels are now clickable (native <label> elements for accessibility).
91 -* Form editor: Section headings use proper h2 elements with consistent styling.
92 -* Form editor: Consistent row heights for style options; color pickers hidden when row is unchecked.
93 -* Form editor: Labels dropdown no longer overflows its container.
94 -* Form editor: Responsive 2-column layout at viewports narrower than 1200px with preview below full-width.
95 -* Form editor: Fixed flash of unstyled content (FOUC) on page load.
96 -* Form editor: Added note under Labels dropdown explaining automatic responsive stacking at 500px.
97 -* i18n: Italian and Spanish translations updated.
76 += 1.9.1 =
77 +* Hardening for potential SQL injection vulnerabilities
98 78
99 -= 2.2.3 =
100 -* Form editor: Added "+" button on each available field to add it to the form with a single click (appends as last, scrolls into view, opens settings).
101 -* Form editor: Hidden the expand caret from available fields list for cleaner UI.
102 -* Form editor: Long field names now wrap to multiple lines instead of being truncated. The "+" button and expand caret remain vertically centered and always clickable.
103 -* i18n: Added Italian translations for new UI strings.
79 += 1.9.0 =
80 +* Checks for unfiltered_html capability and supports limited admin permissions in WordPress multisite configurations
81 +* Filters the list of allowed upload file extensions according get_allowed_mime_types(), and check the maximum upload size with wp_max_upload_size()
82 +* Default date fix
83 +* Other minor fixes
104 84
105 -= 2.2.2 =
106 -* Form editor: Added instant search filter in the Available Fields column — type to quickly find fields by name (substring match).
85 += 1.8.0 =
86 +* Using tinyColorPicker on frontend
87 +* Fixed XSS vulnerability
107 88
108 -= 2.2.1 =
109 -* Form editor: Redesigned Fields tab as a stable three-column CSS Grid layout (available fields, drop zone, live preview). The available fields column has its own scrollbar; the other columns use the main browser scroll. Fixes wrapping issues on high-zoom levels, small screens, and forms with many fields or long labels.
110 -* Form editor: Each column now has its own heading styled consistently and aligned at the same height.
111 -* Form editor: Drop zone title moved outside the dashed border for clearer visual hierarchy.
89 += 1.7.0 =
90 +* Lead status
91 +* Minor fixes
112 92
113 -= 2.2.0 =
114 -* Tested up to WordPress 7.0.
115 -* Added WordPress Playground blueprint for live preview on wordpress.org - five demo forms covering all field types including fieldsets, checkboxes, multi-select, post-select, and HTML blocks.
116 -* Email notifications: Long URLs no longer break print/PDF layout. Applied table-layout fixed and word-break on URL fields.
117 -* Email notifications: Improved vertical spacing between submitted fields with proper cell padding.
118 -* Email notifications: Fieldset labels now display correctly instead of raw field IDs.
119 -* Email notifications: Fixed malformed font-family quotes in the email body wrapper.
120 -* Single submission page: Restructured from 3-column to 2-column (30/70) layout. Details and Lead Status are now in the left column, submitted fields in the right.
121 -* Single submission page: Renamed "Stats" postbox to "Details".
122 -* Single submission page: Long URLs now wrap properly in the submitted fields table.
123 -* Submissions list: Added view links (Active, Trash, Lead Status) for quick filtering.
124 -* Submissions list: Refactored filter controls into native WP_List_Table extra_tablenav pattern.
125 -* Bugfix: Fieldset without a label no longer shows a gap in the border.
126 -* Bugfix: Essential Columns button race condition - column settings no longer lost during batch save.
127 -* Bugfix: Fields page - legacy-format fields now display correctly with proper name/slug fallback.
93 += 1.6.1 =
94 +* Fixed trashed form restore
95 +* Fixed CSRF vulnerability
128 96
129 -= 2.1.4 =
130 -* Responsive sidebyside layout: labels automatically stack on top when the form container is narrower than 500px, using CSS container queries. Works across all themes regardless of viewport width.
97 += 1.6.0 =
98 +* IP masking option
131 99
132 -= 2.1.3 =
133 -* Fixed: Post select field value was not saved to database and not included in notification emails. The submission handler now resolves posts directly instead of relying on empty lazy-loaded options.
100 += 1.5.10 =
101 +* Fixed plugin icon
134 102
135 -= 2.1.2 =
136 -* Form editor: Added submission count with link to the submissions list, displayed inline with the page heading.
137 -* Form editor: Title input now has proper spacing and sizing matching WordPress core post editor styling.
138 -* Form editor: Google Ads and Tokens tabs now use WordPress postbox markup with form-table layout.
139 -* Form editor: Added unsaved changes warning (beforeunload prompt) when the form has been modified.
103 += 1.5.9 =
104 +* Fixed adding more custom HTML fields and fieldsets
140 105
141 -= 2.1.1 =
142 -* Fixed single submission page: restored proper padding and spacing in the Lead status and Notes postbox
143 -* Improved layout alignment for Lead status dropdown and help icon
144 -* Italian: standardized terminology - "compilazione/compilazioni" for submissions, fixed mixed "modulo/moduli" back to "form/forms", translated all missing strings
145 -* Spanish: added ~260 missing translations (Theme Helper, Appearance, Danger Zone, default messages, block editor, GDPR)
106 += 1.5.8 =
107 +* Fixed CSRF vulnerabilities
108 +* Fixed some JavaScript errors due to WordPress filters
109 +* Fixed many minor bugs
146 110
147 -= 2.1.0 =
148 -Admin UI modernization with a more coherent design language aligned with native WordPress admin patterns.
111 += 1.5.7 =
112 +* tested compatibility with WordPress 6.2.0
149 113
150 -* Flat single-level tab bar for the form editor (Fields, Appearance & General, Messages, Data Retention, Google Ads, Tokens)
151 -* Grid-based layout for form field editor and live preview
152 -* Tab navigation on the settings page with ARIA-compliant accessible tabs
153 -* Native WordPress postbox structure for all settings sections
154 -* Messages tab: 2×2 grid layout, accessible radio buttons with fieldset/label, TinyMCE font selector with 10 email-safe fonts
155 -* Default font changed from Lucida Sans to Arial for new forms
156 -* Merged dashboard.css into admin.css, removed dead CSS selectors
157 -* Bugfix: broken CSS selectors caused by panel ID renaming
158 -* Bugfix: Messages, Data Retention, and Tokens panels not properly contained within the tab system
114 += 1.5.6 =
115 +* Fixed CSRF vulnerability
159 116
160 -= 2.0.0 =
117 += 1.5.5 =
118 +* Fixed XSS vulnerabilities
161 119
162 -Major rewrite focused on accessibility, modern admin UI, and GDPR compliance. All existing forms continue to work without changes.
120 += 1.5.4 =
121 +* Graphical changes to default messages
122 +* Fixed some minor bugs
163 123
164 -**Important:** CSS changes (35 removed `!important` declarations) may affect frontend layouts customized via theme CSS. Use Contact Forms > Theme Helper to identify conflicts. Where possible, use the plugin's Appearance tab instead of theme CSS overrides.
124 += 1.5.3 =
125 +* Removed unused code
126 +* Fixed some minor issues
165 127
166 -* Accessibility rewrite: WCAG 2.2 AA / European Accessibility Act compliance
167 -* Inline Labels layout (floating labels)
168 -* Live preview in the form editor
169 -* GDPR data retention, anonymization, and WordPress Privacy API
170 -* Cloudflare Turnstile support (via Simple Cloudflare Turnstile plugin)
171 -* Google reCAPTCHA v2 with built-in key configuration
172 -* Drag-and-drop file upload with keyboard navigation
173 -* Telephone field with E.164 validation and country prefix
174 -* Custom validation messages per field and per form
175 -* Custom CSS class and ID on all field types
176 -* Submissions list with sortable columns, row actions, and Excel export
177 -* Dashboard charts with monthly-by-page breakdown
178 -* Gutenberg block for inserting forms
179 -* Settings page with Danger Zone and deactivation cleanup
180 -* Theme Helper: diagnose CSS conflicts between your theme and Contact Forms
181 -* English, Italian, and Spanish translations
182 -* Plugin Check (PCP) fully compliant
128 += 1.5.2 =
129 +* Fixed critical error when trying to access the dashboard
183 130
184 -For the detailed per-beta changelog, see the plugin's changelog.txt file.
131 += 1.5.1 =
132 +* Renewed UI
133 +* Fixing some minor bugs
185 134
186 -= 1.9.14 =
135 += 1.4.14 =
136 +* Lazy load reCAPTCHA
187 137
188 -* Added Cloudflare Turnstile field integration
138 += 1.4.13 =
139 +* added html attributes to improve SEO
189 140
190 -== Upgrade Notice ==
141 += 1.4.12 =
142 +* Tested compatibility with PHP up to 8.0 and WordPress up to 5.8.1
143 +* reCAPTCHA loaded from recaptcha.net trying to improve accessibility from countries banning google.com domain
144 +* Fixed minor XSS vulnerability reported on wpscan.com by Felipe Restrepo Rodriguez and Sebastian Cruz Cardona. Form title was not sanitized in every place it was used in the admin interface, however this is mitigated by the fact that only admin users with manage_options capability can edit it.
191 145
192 -= 2.0.0 =
193 -Major rewrite: accessibility (WCAG 2.2 AA), GDPR tools, new layouts, spam protection, and modern admin UI. CSS changes may affect custom theme styling -- use Theme Helper to review. All existing forms continue to work.
146 += 1.4.11 =
147 +* avoid "headers already sent" warnings during WordPress cron
148 +
149 += 1.4.10 =
150 +* Tested compatibility with PHP up to 7.4
151 +* After submission, the fragment #formSubmitSuccess-formID is added to the URL, so the page is scrolled to the top of the message, and it's easier to track the submission with tools like Google Analytics
152 +* fragments #formSubmitInvalid-formID and #formSubmitError-formID are added in case of invalid submission or error
153 +* improved loading of reCAPTCHA
154 +* removed unused resources from PFBC library
155 +* colorPicker styles and javascripts now loads only if it's used
156 +* other small bugfixes
157 +
158 += 1.4.9 =
159 +* improved compatibility with Google Tag Manager to track field filled in and form submission
160 +
161 += 1.4.8 =
162 +* fixed compatibility issues with php 7.2
163 +* option to track field filled in and form submission as events on Google Analytics
164 +* workaround to open/download attachments in submissions exported and opened with Microsoft Excel
165 +
166 += 1.4.7 =
167 +* fixed compatibility issue with WordPress 4.8 that made show/hide buttons for field settings in the form editor invisible
168 +* fixed compatibility issues with php 7.0 and 7.1
169 +* fixed strict standards errors
170 +
171 += 1.4.6 =
172 +* restored compatibility with PHP < 5.3
173 +* fixed some strict standards errors
174 +
175 += 1.4.5 =
176 +* Scaled reCAPTCHA 2 area for devices with less than 400px screen width
177 +* More informations about senders and receivers of the form emails in the forms list page
178 +
179 += 1.4.4 =
180 +* Changed text domain of translatable strings to match the plugin slug
181 +* Bulk action to delete permanently trashed submissions
182 +
183 += 1.4.3 =
184 +* Fixed table index length issue that prevented saving submission values of new user of Contact Forms with recent WordPress versions
185 +* Added internationalization info
186 +
187 += 1.4.2 =
188 +* Fixed table definition error that prevented saving submission of new users of Contact Forms 1.4.0
189 +
190 += 1.4.1 =
191 +* Fixed undefined variable in accua-form-api.php on line 29
192 +
193 += 1.4.0 =
194 +* Filter and export by year and month
195 +* Added actions accua_forms_field_added, accua_forms_field_updated and accua_forms_field_deleted
196 +
197 += 1.3.9 =
198 +* better support for reCAPTCHA allowing to enter site keys and use version 2
199 +* fixed visualization bug of reCAPTCHA 1 with new WordPress themes
200 +* fixed bug that prevented editing fields on the page after a form submission
201 +
202 += 1.3.8 =
203 +* fixed incompatibility with WordPress 4.4 that prevented submissions export
204 +
205 += 1.3.7 =
206 +* fixed incompatibility with WordPress 4.4 that caused a PHP error in every page that includes a form
207 +* new token for select, checkbox and radio labels
208 +* changed database table to allow referrers and urls longer than 255 characters
209 +
210 += 1.3.6 =
211 +* Replaced deprecated user level '10' with capability 'manage_options'
212 +
213 += 1.3.5 =
214 +* fixed incompatibility of form editor with WordPress 4.3 and Chrome
215 +* adding rules to robots.txt to allow /wp-admin/js/ and /wp-admin/css/ for styles and scripts included from that folders
216 +
217 += 1.3.4 =
218 +* Password fields now saves the hash value of the password using wp_hash_password
219 +* Field to set the emails "From:" name
220 +* fixed CAPTCHA field incompatibility with CloudFlare RocketLoader and possibly other JavaScript optimizer
221 +* fixed glitch in the "Form fields" area on the "Edit form" page with latest versions of WordPress
222 +
223 += 1.3.3 =
224 +* improved checkboxes, select and radio definition to allow pre-selected options
225 +* fixed PHP 5.5 incompatibility issue. Now the plugin works with PHP from version 5.2 to 5.5
226 +* fixed default value for email, colorpicker and password fields
227 +* allowed removal of elements by a filter after the form generation
228 +
229 += 1.3.2 =
230 +* fixed visualization of color picker field
231 +* workaround to have multiple forms with recaptcha on the same page
232 +
233 += 1.3.1 =
234 +* fixed validation of required fields with multiple values
235 +* show recipient of admin email in form list
236 +* changes in submissions list generation and export to allow usage by other plugins
237 +
238 += 1.3 =
239 +* Spanish translation by Maria Ramos of [WebHostingHub](http://www.webhostinghub.com/)
240 +* Color picker field
241 +* Possibility to insert raw tokens in html messages
242 +* Disabled HTML5 validation of email fields, using JavaScript validation
243 +
244 += 1.2.1 =
245 +* Fixed installation and upgrade process issues introduced in 1.2
246 +* Users who installed 1.2 as their first version reported that submissions where not saved. Upgrading to this version will fix this issue
247 +
248 += 1.2 =
249 +* Fieldsets
250 +* Submissions trash and restore
251 +* Fixed counting of active and deleted forms
252 +* Fixed submission bug in Internet Explorer 8 and previous versions
253 +
254 += 1.1 =
255 +* Added interface to set basic form styles (borders, colors, padding)
256 +* Fixed captcha validation
257 +* Added submission graph by form
258 +* Screenshots removed from the package
259 +* Other minor fixes