| 1 |
<?php |
| 2 |
|
| 3 |
defined('ABSPATH') or die; |
| 4 |
|
| 5 |
?> |
| 6 |
<style> |
| 7 |
<?php |
| 8 |
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CSS is sanitized via fluentformSanitizeCSS() |
| 9 |
echo fluentformSanitizeCSS($generated_css); |
| 10 |
// SECURITY (FINDING-13): $submit_css interpolates the top-level submitButton colours raw |
| 11 |
// (never covered by Updater::sanitizeCustomSubmit), so a background_color of |
| 12 |
// "red}</style><script>..." would break out here. The standalone view already sanitizes; |
| 13 |
// this inline view did not. fluentformSanitizeCSS() blanks any CSS containing a tag pattern. |
| 14 |
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CSS is sanitized via fluentformSanitizeCSS() |
| 15 |
echo fluentformSanitizeCSS($submit_css); |
| 16 |
?> |
| 17 |
</style> |
| 18 |
<div class="ffc_conv_wrapper ffc_inline_form"> |
| 19 |
<div class="frm-fluent-form ff_conv_app fluent_form_<?php echo esc_attr($form_id); ?> ff_conv_app_frame ff_conv_app_<?php echo esc_attr($form_id); ?> ffc_media_hide_mob_<?php echo esc_attr($design['hide_media_on_mobile']); ?>" data-form_id="<?php echo esc_attr($form_id) ?>"> |
| 20 |
<div data-var_name="<?php echo esc_attr($global_var_name); ?>" class="ffc_conv_form" style="width: 100%" id="ffc_app_instance_<?php echo esc_attr($instance_id); ?>"></div> |
| 21 |
</div> |
| 22 |
</div> |
| 23 |
|