PluginProbe
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder / 6.2.15
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder v6.2.15
6.2.15 6.2.14 6.2.13 6.2.12 6.2.10 6.2.11 6.2.9 6.2.8 6.2.7 6.2.6 6.2.5 6.2.4 6.2.3 6.2.2 3.6.22 3.6.31 3.6.40 3.6.41 3.6.42 3.6.50 3.6.51 3.6.60 3.6.61 3.6.62 3.6.64 All 197 releases
← All changes | app/Services/Form/FormValidationService.php +18 -11 6.2.13 → 6.2.15 View file →
@@ -427,10 +427,12 @@
427 427 if (!wp_verify_nonce($nonce, 'fluentform-submit-form')) {
428 428 $errors = apply_filters_deprecated(
429 429 'fluentForm_nonce_error',
430 430 [
431 - '_fluentformnonce' => [
432 - __('Nonce verification failed, please try again.', 'fluentform'),
431 + [
432 + '_fluentformnonce' => [
433 + __('Nonce verification failed, please try again.', 'fluentform'),
434 + ],
433 435 ],
434 436 ],
435 437 FLUENTFORM_FRAMEWORK_UPGRADE,
436 438 'fluentForm/nonce_error',
@@ -436,9 +438,9 @@
436 438 'fluentForm/nonce_error',
437 439 'Use fluentForm/nonce_error instead of fluentForm_nonce_error.'
438 440 );
439 441
440 - $errors = $this->app->applyFilters('fluentForm/nonce_error', $errors);
442 + $errors = $this->app->applyFilters('fluentform/nonce_error', $errors);
441 443 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- Exception message, not output
442 444 throw new ValidationException('', 422, null, ['errors' => $errors]);
443 445 }
444 446 }
@@ -539,8 +541,12 @@
539 541 }
540 542
541 543 public function isCleanTalkSpam($formData, $form)
542 544 {
545 + if (CleanTalkHandler::isCleantalkActivated() || CleanTalkHandler::hasExecuted()) {
546 + return false;
547 + }
548 +
543 549 if (!CleanTalkHandler::isEnabled()) {
544 550 return false;
545 551 }
546 552 $isSpamCheck = apply_filters('fluentform/cleantalk_check_spam', true, $form->id, $formData);
@@ -1134,13 +1140,13 @@
1134 1140 * - Han, Kana, Thai, Lao, Khmer, Myanmar and Tibetan don't separate words at
1135 1141 * all, so no boundary can ever exist around a keyword. Whole-word is
1136 1142 * meaningless there and the keyword is matched as a substring instead.
1137 1143 *
1138 - * Everything else — underscore, zero-width joiners, non-ASCII digits — stays
1139 - * a separator, matching the class the previous implementation tokenised on.
1140 - * That keeps this a strict superset of the old matcher: a keyword that used
1141 - * to be blocked is still blocked, and padding a keyword with an invisible
1142 - * ZWNJ can't slip it past the filter.
1144 + * The neighbouring-character guard covers base letters and digits. Marks
1145 + * that are part of the keyword remain in the quoted literal, while a mark
1146 + * appended after a keyword cannot turn into a bypass. Everything else —
1147 + * underscore, zero-width joiners and punctuation — stays a separator,
1148 + * matching the class the previous implementation tokenised on.
1143 1149 *
1144 1150 * @param string $keyword
1145 1151 * @return string
1146 1152 */
@@ -1151,14 +1157,15 @@
1151 1157 if (preg_match('/[\p{Han}\p{Hiragana}\p{Katakana}\p{Thai}\p{Lao}\p{Khmer}\p{Myanmar}\p{Tibetan}]/u', $keyword)) {
1152 1158 return '/' . $quoted . '/ui';
1153 1159 }
1154 1160
1155 - $wordChar = '\p{L}\p{M}\d';
1161 + $edgeChar = '\p{L}\p{M}\d';
1162 + $neighborChar = '\p{L}\d';
1156 1163
1157 1164 // Only guard an edge that is itself a word character, so keywords
1158 1165 // wrapped in punctuation (e.g. "$$$" or "buy!") stay matchable.
1159 - $lead = preg_match('/^[' . $wordChar . ']/u', $keyword) ? '(?<![' . $wordChar . '])' : '';
1160 - $trail = preg_match('/[' . $wordChar . ']$/u', $keyword) ? '(?![' . $wordChar . '])' : '';
1166 + $lead = preg_match('/^[' . $edgeChar . ']/u', $keyword) ? '(?<![' . $neighborChar . '])' : '';
1167 + $trail = preg_match('/[' . $edgeChar . ']$/u', $keyword) ? '(?![' . $neighborChar . '])' : '';
1161 1168
1162 1169 return '/' . $lead . $quoted . $trail . '/ui';
1163 1170 }
1164 1171