PluginProbe
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder / 6.2.15
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder v6.2.15
6.2.15 6.2.14 6.2.13 6.2.12 6.2.10 6.2.11 6.2.9 6.2.8 6.2.7 6.2.6 6.2.5 6.2.4 6.2.3 6.2.2 3.6.22 3.6.31 3.6.40 3.6.41 3.6.42 3.6.50 3.6.51 3.6.60 3.6.61 3.6.62 3.6.64 All 197 releases
← All changes | app/Hooks/Ajax.php +22 -10 6.2.9 → 6.2.15 View file →
@@ -34,12 +34,12 @@
34 34 $data = $app->request->all();
35 35 $data['form_id'] = $formId;
36 36 $isValidJson = (!empty($data['formFields'])) && json_decode($data['formFields'], true);
37 37
38 - if(!$isValidJson) {
38 + if (!$isValidJson) {
39 39 wp_send_json([
40 40 'message' => 'Looks like the provided JSON is invalid. Please try again or contact support',
41 - 'reason' => 'formFields JSON validation failed'
41 + 'reason' => 'formFields JSON validation failed',
42 42 ], 422);
43 43 }
44 44
45 45 $formService = new \FluentForm\App\Services\Form\FormService();
@@ -44,9 +44,9 @@
44 44
45 45 $formService = new \FluentForm\App\Services\Form\FormService();
46 46 $form = $formService->update($data);
47 47 wp_send_json([
48 - 'message' => __('The form is successfully updated.', 'fluentform')
48 + 'message' => __('The form is successfully updated.', 'fluentform'),
49 49 ], 200);
50 50 } catch (\Exception $exception) {
51 51 wp_send_json([
52 52 'message' => $exception->getMessage(),
@@ -143,15 +143,27 @@
143 143 wp_send_json_error(['message' => $e->getMessage()], 423);
144 144 }
145 145 });
146 146
147 -$app->addAction('wp_ajax_fluentform-get-users', function () use ($app) {
148 - Acl::verify('fluentform_entries_viewer');
147 +$app->addAction('wp_ajax_fluentform-get-users', function () use ($app, $resolveSubmissionFormId) {
148 + $submissionId = absint($app->request->get('submission_id'));
149 + $formId = Acl::verifyFormId(
150 + $resolveSubmissionFormId($submissionId),
151 + 'Invalid submission id.'
152 + );
153 +
154 + Acl::verify('fluentform_manage_entries', $formId);
149 155 $search = sanitize_text_field($app->request->get('search'));
150 - $users = get_users([
151 - 'search' => "*{$search}*",
152 - 'number' => 50,
153 - ]);
156 + if (current_user_can('list_users')) {
157 + $users = get_users([
158 + 'search' => "*{$search}*",
159 + 'number' => 50,
160 + ]);
161 + } else {
162 + // Non-admins confirm an exact email only, never browse the roster (FF-SEC-45).
163 + $user = is_email($search) ? get_user_by('email', $search) : false;
164 + $users = $user ? [$user] : [];
165 + }
154 166 $formattedUsers = [];
155 167 foreach ($users as $user) {
156 168 $formattedUsers[] = [
157 169 'ID' => $user->ID,
@@ -240,9 +252,9 @@
240 252 wp_send_json([
241 253 'error' => 'You do not have permission to do this',
242 254 ], 403);
243 255 }
244 -
256 +
245 257 wp_send_json([
246 258 'nonce' => wp_create_nonce('wp_rest'),
247 259 ], 200);
248 260 });