| @@ -427,10 +427,12 @@ | ||
| 427 | 427 | if (!wp_verify_nonce($nonce, 'fluentform-submit-form')) { |
| 428 | 428 | $errors = apply_filters_deprecated( |
| 429 | 429 | 'fluentForm_nonce_error', |
| 430 | 430 | [ |
| 431 | - '_fluentformnonce' => [ | |
| 432 | - __('Nonce verification failed, please try again.', 'fluentform'), | |
| 431 | + [ | |
| 432 | + '_fluentformnonce' => [ | |
| 433 | + __('Nonce verification failed, please try again.', 'fluentform'), | |
| 434 | + ], | |
| 433 | 435 | ], |
| 434 | 436 | ], |
| 435 | 437 | FLUENTFORM_FRAMEWORK_UPGRADE, |
| 436 | 438 | 'fluentForm/nonce_error', |
| @@ -436,9 +438,9 @@ | ||
| 436 | 438 | 'fluentForm/nonce_error', |
| 437 | 439 | 'Use fluentForm/nonce_error instead of fluentForm_nonce_error.' |
| 438 | 440 | ); |
| 439 | 441 | |
| 440 | - $errors = $this->app->applyFilters('fluentForm/nonce_error', $errors); | |
| 442 | + $errors = $this->app->applyFilters('fluentform/nonce_error', $errors); | |
| 441 | 443 | // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- Exception message, not output |
| 442 | 444 | throw new ValidationException('', 422, null, ['errors' => $errors]); |
| 443 | 445 | } |
| 444 | 446 | } |
| @@ -539,8 +541,12 @@ | ||
| 539 | 541 | } |
| 540 | 542 | |
| 541 | 543 | public function isCleanTalkSpam($formData, $form) |
| 542 | 544 | { |
| 545 | + if (CleanTalkHandler::isCleantalkActivated() || CleanTalkHandler::hasExecuted()) { | |
| 546 | + return false; | |
| 547 | + } | |
| 548 | + | |
| 543 | 549 | if (!CleanTalkHandler::isEnabled()) { |
| 544 | 550 | return false; |
| 545 | 551 | } |
| 546 | 552 | $isSpamCheck = apply_filters('fluentform/cleantalk_check_spam', true, $form->id, $formData); |
| @@ -1134,13 +1140,13 @@ | ||
| 1134 | 1140 | * - Han, Kana, Thai, Lao, Khmer, Myanmar and Tibetan don't separate words at |
| 1135 | 1141 | * all, so no boundary can ever exist around a keyword. Whole-word is |
| 1136 | 1142 | * meaningless there and the keyword is matched as a substring instead. |
| 1137 | 1143 | * |
| 1138 | - * Everything else — underscore, zero-width joiners, non-ASCII digits — stays | |
| 1139 | - * a separator, matching the class the previous implementation tokenised on. | |
| 1140 | - * That keeps this a strict superset of the old matcher: a keyword that used | |
| 1141 | - * to be blocked is still blocked, and padding a keyword with an invisible | |
| 1142 | - * ZWNJ can't slip it past the filter. | |
| 1144 | + * The neighbouring-character guard covers base letters and digits. Marks | |
| 1145 | + * that are part of the keyword remain in the quoted literal, while a mark | |
| 1146 | + * appended after a keyword cannot turn into a bypass. Everything else — | |
| 1147 | + * underscore, zero-width joiners and punctuation — stays a separator, | |
| 1148 | + * matching the class the previous implementation tokenised on. | |
| 1143 | 1149 | * |
| 1144 | 1150 | * @param string $keyword |
| 1145 | 1151 | * @return string |
| 1146 | 1152 | */ |
| @@ -1151,14 +1157,15 @@ | ||
| 1151 | 1157 | if (preg_match('/[\p{Han}\p{Hiragana}\p{Katakana}\p{Thai}\p{Lao}\p{Khmer}\p{Myanmar}\p{Tibetan}]/u', $keyword)) { |
| 1152 | 1158 | return '/' . $quoted . '/ui'; |
| 1153 | 1159 | } |
| 1154 | 1160 | |
| 1155 | - $wordChar = '\p{L}\p{M}\d'; | |
| 1161 | + $edgeChar = '\p{L}\p{M}\d'; | |
| 1162 | + $neighborChar = '\p{L}\d'; | |
| 1156 | 1163 | |
| 1157 | 1164 | // Only guard an edge that is itself a word character, so keywords |
| 1158 | 1165 | // wrapped in punctuation (e.g. "$$$" or "buy!") stay matchable. |
| 1159 | - $lead = preg_match('/^[' . $wordChar . ']/u', $keyword) ? '(?<![' . $wordChar . '])' : ''; | |
| 1160 | - $trail = preg_match('/[' . $wordChar . ']$/u', $keyword) ? '(?![' . $wordChar . '])' : ''; | |
| 1166 | + $lead = preg_match('/^[' . $edgeChar . ']/u', $keyword) ? '(?<![' . $neighborChar . '])' : ''; | |
| 1167 | + $trail = preg_match('/[' . $edgeChar . ']$/u', $keyword) ? '(?![' . $neighborChar . '])' : ''; | |
| 1161 | 1168 | |
| 1162 | 1169 | return '/' . $lead . $quoted . $trail . '/ui'; |
| 1163 | 1170 | } |
| 1164 | 1171 | |