PluginProbe
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages / 3.4.6
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages v3.4.6
3.4.6 3.4.5 3.4.4 3.4.3 3.4.2 3.4.1 3.4.0 3.3.9 3.3.8 3.3.7 3.3.6 3.3.5 3.3.4 3.3.3 3.3.2 3.3.1 2.2.0 2.2.1 2.2.2 2.2.3 2.2.4 2.2.5 2.2.6 2.2.7 2.2.8 All 199 releases
← All changes | includes/integrations/forminator/class-convertkit-forminator.php +24 -5 3.3.2 → 3.4.6 View file →
@@ -76,8 +76,13 @@
76 76 * @param array $form_data_array Forminator submitted data.
77 77 */
78 78 public function maybe_subscribe( $entry, $form_id, $form_data_array ) {
79 79
80 + // Bail if the entry is spam, a draft or an abandoned form.
81 + if ( ! empty( $entry->is_spam ) || $entry->status !== 'active' ) {
82 + return;
83 + }
84 +
80 85 // Get ConvertKit Form ID mapped to this Forminator Form.
81 86 // We deliberately use the entry's form ID, as $form_id for a Quiz will point to a lead generation form, which
82 87 // has a different Form ID.
83 88 $forminator_settings = new ConvertKit_Forminator_Settings();
@@ -105,8 +110,14 @@
105 110
106 111 // Extract the name / email address, depending on the field type.
107 112 switch ( $form_field['field_type'] ) {
108 113 case 'name':
114 + // If the Name field uses multiple fields (prefix, first, middle and last name), use the first name.
115 + if ( is_array( $form_field['value'] ) ) {
116 + $first_name = isset( $form_field['value']['first-name'] ) ? $form_field['value']['first-name'] : false;
117 + break;
118 + }
119 +
109 120 $name = explode( ' ', $form_field['value'] );
110 121 $first_name = $name[0];
111 122 break;
112 123
@@ -153,8 +164,13 @@
153 164 case 'form':
154 165 // Subscribe with inactive state.
155 166 $subscriber = $api->create_subscriber( $email, $first_name, 'inactive' );
156 167
168 + // If an error occurred, don't attempt to add the subscriber to the Form, as it won't work.
169 + if ( is_wp_error( $subscriber ) ) {
170 + return;
171 + }
172 +
157 173 // For Legacy Forms, a different endpoint is used.
158 174 $forms = new ConvertKit_Resource_Forms();
159 175 if ( $forms->is_legacy( $resource_id ) ) {
160 176 return $api->add_subscriber_to_legacy_form( $resource_id, $subscriber['subscriber']['id'] );
@@ -169,9 +185,9 @@
169 185 case 'sequence':
170 186 // Subscribe.
171 187 $subscriber = $api->create_subscriber( $email, $first_name );
172 188
173 - // If an error occured, don't attempt to add the subscriber to the Form, as it won't work.
189 + // If an error occurred, don't attempt to add the subscriber to the Form, as it won't work.
174 190 if ( is_wp_error( $subscriber ) ) {
175 191 return;
176 192 }
177 193
@@ -184,9 +200,9 @@
184 200 case 'tag':
185 201 // Subscribe.
186 202 $subscriber = $api->create_subscriber( $email, $first_name );
187 203
188 - // If an error occured, don't attempt to add the subscriber to the Form, as it won't work.
204 + // If an error occurred, don't attempt to add the subscriber to the Form, as it won't work.
189 205 if ( is_wp_error( $subscriber ) ) {
190 206 return;
191 207 }
192 208
@@ -211,16 +227,19 @@
211 227
212 228 // If the request includes the HTTP referrer, return that URL
213 229 // as it will include any UTM parameters.
214 230 if ( filter_has_var( INPUT_POST, '_wp_http_referer' ) ) {
215 - // referrer is a relative path, so use home_url() to return a fully qualified URL.
216 - return esc_url( home_url( filter_input( INPUT_POST, '_wp_http_referer', FILTER_SANITIZE_FULL_SPECIAL_CHARS ) ) );
231 + // referrer is relative to the domain and includes any subdirectory, so prefix it with the site's scheme, host and port.
232 + $home = wp_parse_url( home_url() );
233 + return esc_url_raw(
234 + $home['scheme'] . '://' . $home['host'] . ( isset( $home['port'] ) ? ':' . $home['port'] : '' ) . filter_input( INPUT_POST, '_wp_http_referer', FILTER_UNSAFE_RAW )
235 + );
217 236 }
218 237
219 238 // If the request includes the current_url, return that URL.
220 239 // It won't include any UTM parameters, but is still an accurate URL.
221 240 if ( filter_has_var( INPUT_POST, 'current_url' ) ) {
222 - return esc_url( filter_input( INPUT_POST, 'current_url', FILTER_SANITIZE_FULL_SPECIAL_CHARS ) );
241 + return esc_url_raw( filter_input( INPUT_POST, 'current_url', FILTER_UNSAFE_RAW ) );
223 242 }
224 243
225 244 // Return the AJAX URL.
226 245 return home_url( add_query_arg( null, null ) );