| @@ -98,28 +98,39 @@ | ||
| 98 | 98 | |
| 99 | 99 | // Inspect response. |
| 100 | 100 | $body = json_decode( wp_remote_retrieve_body( $response ), true ); |
| 101 | 101 | |
| 102 | + // If the response body couldn't be decoded, treat that as a failure. | |
| 103 | + if ( ! is_array( $body ) ) { | |
| 104 | + return new WP_Error( | |
| 105 | + 'convertkit_recaptcha_failed', | |
| 106 | + __( 'Google reCAPTCHA failure: invalid response from siteverify.', 'convertkit' ) | |
| 107 | + ); | |
| 108 | + } | |
| 109 | + | |
| 102 | 110 | // If the request wasn't successful, return an error. |
| 103 | - if ( ! $body['success'] ) { | |
| 111 | + if ( empty( $body['success'] ) ) { | |
| 104 | 112 | return new WP_Error( |
| 105 | 113 | 'convertkit_recaptcha_failed', |
| 106 | 114 | sprintf( |
| 107 | 115 | /* translators: Error codes */ |
| 108 | 116 | __( 'Google reCAPTCHA failure: %s', 'convertkit' ), |
| 109 | - implode( ', ', $body['error-codes'] ) | |
| 117 | + implode( ', ', isset( $body['error-codes'] ) ? (array) $body['error-codes'] : array() ) | |
| 110 | 118 | ) |
| 111 | 119 | ); |
| 112 | 120 | } |
| 113 | 121 | |
| 114 | - // Return if the action doesn't match the Plugin action, this might not be a reCAPTCHA request | |
| 115 | - // for this request. | |
| 116 | - if ( $body['action'] !== $plugin_action ) { | |
| 117 | - return true; | |
| 122 | + // If the action doesn't match the Plugin action, the token was generated for a different action. | |
| 123 | + // Treat this as a failure, so the minimum score check can't be bypassed. | |
| 124 | + if ( ! isset( $body['action'] ) || $body['action'] !== $plugin_action ) { | |
| 125 | + return new WP_Error( | |
| 126 | + 'convertkit_recaptcha_failed', | |
| 127 | + __( 'Google reCAPTCHA failed', 'convertkit' ) | |
| 128 | + ); | |
| 118 | 129 | } |
| 119 | 130 | |
| 120 | 131 | // If the score is less than the required minimum score, it's likely a spam submission. |
| 121 | - if ( $body['score'] < $this->settings->recaptcha_minimum_score() ) { | |
| 132 | + if ( ! isset( $body['score'] ) || $body['score'] < $this->settings->recaptcha_minimum_score() ) { | |
| 122 | 133 | return new WP_Error( |
| 123 | 134 | 'convertkit_recaptcha_failed', |
| 124 | 135 | __( 'Google reCAPTCHA failed', 'convertkit' ) |
| 125 | 136 | ); |