PluginProbe
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder / 6.2.15
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder v6.2.15
6.2.15 6.2.14 6.2.13 6.2.12 6.2.10 6.2.11 6.2.9 6.2.8 6.2.7 6.2.6 6.2.5 6.2.4 6.2.3 6.2.2 3.6.22 3.6.31 3.6.40 3.6.41 3.6.42 3.6.50 3.6.51 3.6.60 3.6.61 3.6.62 3.6.64 All 197 releases
← All changes | app/Modules/Component/Component.php +13 -4 6.2.9 → 6.2.15 View file →
@@ -885,10 +885,19 @@
885 885 if (isset($attrDefaultValues['{payment_total}'])) {
886 886 $attrDefaultValues['{payment_total}'] = '<span class="ff_order_total"></span>';
887 887 }
888 888
889 - // Finally, replace the patterns with the replacements and return the output HTML.
890 - return str_replace(array_keys($attrDefaultValues), array_values($attrDefaultValues), $output);
889 + // Replace in a single pass. str_replace() with arrays re-scans text an earlier key inserted,
890 + // so ?a=javascript{get.b}&b=:alert(1) would assemble a script URL from two escaped values.
891 + $replacements = [];
892 + foreach ($attrDefaultValues as $pattern => $replacement) {
893 + // strtr() returns false on an empty key before PHP 8.
894 + if ('' !== (string) $pattern && (is_scalar($replacement) || null === $replacement)) {
895 + $replacements[(string) $pattern] = (string) $replacement;
896 + }
897 + }
898 +
899 + return strtr($output, $replacements);
891 900 }
892 901
893 902 /**
894 903 * Register renderer actions for compiling each element
@@ -1376,9 +1385,9 @@
1376 1385 $dateFormat = $atts['date_format'];
1377 1386 } else {
1378 1387 $dateFormat = get_option('date_format') . ' ' . get_option('time_format');
1379 1388 }
1380 - return date($dateFormat, strtotime($form->created_at));
1389 + return esc_html(date($dateFormat, strtotime($form->created_at)));
1381 1390 } elseif ('updated_at' == $atts['info']) {
1382 1391 if ($atts['date_format']) {
1383 1392 $dateFormat = $atts['date_format'];
1384 1393 } else {
@@ -1383,9 +1392,9 @@
1383 1392 $dateFormat = $atts['date_format'];
1384 1393 } else {
1385 1394 $dateFormat = get_option('date_format') . ' ' . get_option('time_format');
1386 1395 }
1387 - return date($dateFormat, strtotime($form->updated_at));
1396 + return esc_html(date($dateFormat, strtotime($form->updated_at)));
1388 1397 } elseif ('payment_total' == $atts['info']) {
1389 1398 if (!defined('FLUENTFORMPRO')) {
1390 1399 return '';
1391 1400 }