PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / 5.0
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More v5.0
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/controllers/FrmAddonsController.php +41 -224 6.35.0 View file →
@@ -4,16 +4,8 @@
4 4 }
5 5
6 6 class FrmAddonsController {
7 7
8 - /**
9 - * @var string $plugin
10 - */
11 - protected static $plugin;
12 -
13 - /**
14 - * @return void
15 - */
16 8 public static function menu() {
17 9 if ( ! current_user_can( 'activate_plugins' ) ) {
18 10 return;
19 11 }
@@ -37,11 +29,8 @@
37 29 exit;
38 30 }
39 31 }
40 32
41 - /**
42 - * @return void
43 - */
44 33 public static function list_addons() {
45 34 FrmAppHelper::include_svg();
46 35 $installed_addons = apply_filters( 'frm_installed_addons', array() );
47 36 $license_type = '';
@@ -72,11 +61,8 @@
72 61
73 62 include( FrmAppHelper::plugin_path() . '/classes/views/addons/list.php' );
74 63 }
75 64
76 - /**
77 - * @return void
78 - */
79 65 public static function license_settings() {
80 66 $plugins = apply_filters( 'frm_installed_addons', array() );
81 67 if ( empty( $plugins ) ) {
82 68 esc_html_e( 'There are no plugins on your site that require a license', 'formidable' );
@@ -88,11 +74,8 @@
88 74
89 75 include( FrmAppHelper::plugin_path() . '/classes/views/addons/settings.php' );
90 76 }
91 77
92 - /**
93 - * @return array
94 - */
95 78 protected static function get_api_addons() {
96 79 $api = new FrmFormApi();
97 80 $addons = $api->get_api_info();
98 81
@@ -123,10 +106,10 @@
123 106 'docs' => '',
124 107 'excerpt' => 'Enhance your basic Formidable forms with a plethora of Pro field types and features. Create advanced forms and data-driven applications in minutes.',
125 108 ),
126 109 'mailchimp' => array(
127 - 'title' => 'Mailchimp Forms',
128 - 'excerpt' => 'Get on the path to more sales and leads in a matter of minutes. Add leads to a Mailchimp mailing list when they submit forms and update their information along with the entry.',
110 + 'title' => 'MailChimp Forms',
111 + 'excerpt' => 'Get on the path to more sales and leads in a matter of minutes. Add leads to a MailChimp mailing list when they submit forms and update their information along with the entry.',
129 112 ),
130 113 'registration' => array(
131 114 'title' => 'User Registration Forms',
132 115 'link' => 'downloads/user-registration/',
@@ -188,13 +171,8 @@
188 171 'views' => array(
189 172 'title' => 'Formidable Views',
190 173 'excerpt' => 'Add the power of views to your Formidable Forms to display your form submissions in listings, tables, calendars, and more.',
191 174 ),
192 - 'quiz_maker' => array(
193 - 'title' => 'Quiz Maker',
194 - 'link' => 'downloads/quiz-maker/',
195 - 'excerpt' => 'Make quizzes, automatically score them and show user scores.',
196 - ),
197 175 );
198 176
199 177 $defaults = array(
200 178 'released' => '',
@@ -251,11 +229,8 @@
251 229 }
252 230
253 231 /**
254 232 * @since 4.08
255 - *
256 - * @param array $addons
257 - * @return array
258 233 */
259 234 protected static function get_pro_from_addons( $addons ) {
260 235 return isset( $addons['93790'] ) ? $addons['93790'] : array();
261 236 }
@@ -297,10 +272,8 @@
297 272 }
298 273
299 274 /**
300 275 * @since 4.08
301 - *
302 - * @return array|false
303 276 */
304 277 protected static function get_primary_license_info() {
305 278 $installed_addons = apply_filters( 'frm_installed_addons', array() );
306 279 if ( empty( $installed_addons ) || ! isset( $installed_addons['formidable_pro'] ) ) {
@@ -330,12 +303,17 @@
330 303 if ( empty( $installed_addons ) ) {
331 304 return $transient;
332 305 }
333 306
334 - $version_info = self::fill_update_addon_info( $installed_addons );
307 + $version_info = self::fill_update_addon_info( $installed_addons );
308 +
335 309 $transient->last_checked = time();
336 - $wp_plugins = self::get_plugins();
337 310
311 + if ( ! function_exists( 'get_plugins' ) ) {
312 + require_once ABSPATH . 'wp-admin/includes/plugin.php';
313 + }
314 + $wp_plugins = get_plugins();
315 +
338 316 foreach ( $version_info as $id => $plugin ) {
339 317 $plugin = (object) $plugin;
340 318
341 319 if ( ! isset( $plugin->new_version ) || ! isset( $plugin->package ) ) {
@@ -368,23 +346,8 @@
368 346 return $transient;
369 347 }
370 348
371 349 /**
372 - * Copy of FrmAppHelper::get_plugins.
373 - * Because this gets called on "pre_set_site_transient_update_plugins" an old version of FrmAppHelper may be loaded on plugin update.
374 - * This means that trying to access FrmAppHelper::get_plugins when upgrading from a Lite version before v5.5 results in a one-off error.
375 - *
376 - * @since 5.5.2
377 - * @return array
378 - */
379 - protected static function get_plugins() {
380 - if ( ! function_exists( 'get_plugins' ) ) {
381 - require_once ABSPATH . 'wp-admin/includes/plugin.php';
382 - }
383 - return get_plugins();
384 - }
385 -
386 - /**
387 350 * Check if a plugin is installed before showing an update for it
388 351 *
389 352 * @since 3.05
390 353 *
@@ -392,9 +355,14 @@
392 355 *
393 356 * @return bool - True if installed
394 357 */
395 358 protected static function is_installed( $plugin ) {
396 - $all_plugins = self::get_plugins();
359 + if ( ! function_exists( 'get_plugins' ) ) {
360 + require_once ABSPATH . 'wp-admin/includes/plugin.php';
361 + }
362 +
363 + $all_plugins = get_plugins();
364 +
397 365 return isset( $all_plugins[ $plugin ] );
398 366 }
399 367
400 368 /**
@@ -480,13 +448,8 @@
480 448
481 449 if ( ! empty( $link ) ) {
482 450 $link['status'] = $addon['status']['type'];
483 451 }
484 - } elseif ( current_user_can( 'activate_plugins' ) && self::is_installed( 'formidable-' . $plugin . '/formidable-' . $plugin . '.php' ) ) {
485 - $link = array(
486 - 'url' => 'formidable-' . $plugin . '/formidable-' . $plugin . '.php',
487 - 'class' => 'frm-activate-addon',
488 - );
489 452 }
490 453
491 454 return $link;
492 455 }
@@ -544,11 +507,8 @@
544 507
545 508 return $plugin;
546 509 }
547 510
548 - /**
549 - * @return void
550 - */
551 511 protected static function prepare_addons( &$addons ) {
552 512 $activate_url = '';
553 513 if ( current_user_can( 'activate_plugins' ) ) {
554 514 $activate_url = add_query_arg( array( 'action' => 'activate' ), admin_url( 'plugins.php' ) );
@@ -571,19 +531,12 @@
571 531 $addon['plugin'] = $file_name;
572 532 }
573 533 }
574 534
575 - $addon['installed'] = self::is_installed( $file_name );
576 - if ( $addon['installed'] && 'formidable-views/formidable-views.php' === $file_name ) {
577 - $active_views_version = self::get_active_views_version();
578 - if ( false !== $active_views_version && $slug !== $active_views_version ) {
579 - $addon['installed'] = false;
580 - }
581 - }
582 -
535 + $addon['installed'] = self::is_installed( $file_name );
583 536 $addon['activate_url'] = '';
584 537
585 - if ( $addon['installed'] && ! empty( $activate_url ) && ! self::is_plugin_active( $file_name, $slug ) ) {
538 + if ( $addon['installed'] && ! empty( $activate_url ) && ! is_plugin_active( $file_name ) ) {
586 539 $addon['activate_url'] = add_query_arg(
587 540 array(
588 541 '_wpnonce' => wp_create_nonce( 'activate-plugin_' . $file_name ),
589 542 'plugin' => $file_name,
@@ -607,32 +560,9 @@
607 560 }
608 561 }
609 562
610 563 /**
611 - * @return bool
612 - */
613 - private static function is_plugin_active( $file_name, $slug ) {
614 - if ( 'formidable-views/formidable-views.php' === $file_name ) {
615 - return self::get_active_views_version() === $slug;
616 - }
617 - return is_plugin_active( $file_name );
618 - }
619 -
620 - /**
621 - * @return string|false either 'visual-views' or 'views', false if one is not found.
622 - */
623 - private static function get_active_views_version() {
624 - if ( ! is_callable( 'FrmViewsAppHelper::plugin_version' ) ) {
625 - return false;
626 - }
627 - $plugin_version = FrmViewsAppHelper::plugin_version();
628 - return version_compare( $plugin_version, '5.0', '>=' ) ? 'visual-views' : 'views';
629 - }
630 -
631 - /**
632 564 * @since 3.04.02
633 - *
634 - * @return void
635 565 */
636 566 protected static function prepare_addon_link( &$link ) {
637 567 $site_url = 'https://formidableforms.com/';
638 568 if ( strpos( $link, 'http' ) !== 0 ) {
@@ -651,10 +581,8 @@
651 581 * Add the status to the addon array. Status options are:
652 582 * installed, active, not installed
653 583 *
654 584 * @since 3.04.02
655 - *
656 - * @return void
657 585 */
658 586 protected static function set_addon_status( &$addon ) {
659 587 if ( ! empty( $addon['activate_url'] ) ) {
660 588 $addon['status'] = array(
@@ -673,11 +601,8 @@
673 601 );
674 602 }
675 603 }
676 604
677 - /**
678 - * @return void
679 - */
680 605 public static function upgrade_to_pro() {
681 606 FrmAppHelper::include_svg();
682 607
683 608 $link_parts = array(
@@ -887,16 +812,14 @@
887 812 /**
888 813 * Install Pro after connection with Formidable.
889 814 *
890 815 * @since 4.02.05
891 - *
892 - * @return void
893 816 */
894 817 public static function connect_pro() {
895 818 FrmAppHelper::permission_check( 'install_plugins' );
896 819 check_ajax_referer( 'frm_ajax', 'nonce' );
897 820
898 - $url = self::get_current_plugin();
821 + $url = FrmAppHelper::get_post_param( 'plugin', '', 'sanitize_text_field' );
899 822 if ( FrmAppHelper::pro_is_installed() || empty( $url ) ) {
900 823 wp_die();
901 824 }
902 825
@@ -902,9 +825,9 @@
902 825
903 826 $response = array();
904 827
905 828 // It's already installed and active.
906 - $active = self::activate_plugin( 'formidable-pro/formidable-pro.php', false, false, true );
829 + $active = activate_plugin( 'formidable-pro/formidable-pro.php', false, false, true );
907 830 if ( is_wp_error( $active ) ) {
908 831 // The plugin was installed, but not active. Download it now.
909 832 self::ajax_install_addon();
910 833 } else {
@@ -916,41 +839,15 @@
916 839 wp_die();
917 840 }
918 841
919 842 /**
920 - * @since 5.5.2
921 - *
922 - * @param string $plugin
923 - * @param string $redirect
924 - * @param bool $network_wide
925 - * @param bool $silent
926 - * @return null|WP_Error Null on success, WP_Error on invalid file.
927 - */
928 - protected static function activate_plugin( $plugin, $redirect = '', $network_wide = false, $silent = false ) {
929 - if ( ! function_exists( 'activate_plugin' ) ) {
930 - require_once ABSPATH . 'wp-admin/includes/plugin.php';
931 - }
932 - return activate_plugin( $plugin, $redirect, $network_wide, $silent );
933 - }
934 -
935 - /**
936 - * @since 5.0.10
937 - *
938 - * @return string
939 - */
940 - protected static function get_current_plugin() {
941 - if ( ! isset( self::$plugin ) ) {
942 - self::$plugin = FrmAppHelper::get_param( 'plugin', '', 'post', 'esc_url_raw' );
943 - }
944 - return self::$plugin;
945 - }
946 -
947 - /**
948 843 * @since 4.08
949 844 */
950 845 protected static function download_and_activate() {
846 + // Set the current screen to avoid undefined notices.
951 847 if ( is_admin() ) {
952 - FrmAppHelper::set_current_screen_and_hook_suffix();
848 + global $hook_suffix;
849 + set_current_screen();
953 850 }
954 851
955 852 self::maybe_show_cred_form();
956 853
@@ -962,10 +859,8 @@
962 859 }
963 860
964 861 /**
965 862 * @since 3.04.02
966 - *
967 - * @return void
968 863 */
969 864 protected static function maybe_show_cred_form() {
970 865 if ( ! function_exists( 'request_filesystem_credentials' ) ) {
971 866 include_once( ABSPATH . 'wp-admin/includes/file.php' );
@@ -1002,24 +897,8 @@
1002 897 ob_end_clean();
1003 898 }
1004 899
1005 900 /**
1006 - * Checks if an addon download url is allowed.
1007 - *
1008 - * @since 6.2
1009 - *
1010 - * @param string $download_url
1011 - *
1012 - * @return bool
1013 - */
1014 - public static function url_is_allowed( $download_url ) {
1015 - return (
1016 - FrmAppHelper::validate_url_is_in_s3_bucket( $download_url, 'zip' ) ||
1017 - ( strpos( $download_url, 'https://downloads.wordpress.org/plugin' ) === 0 && substr_compare( $download_url, '.zip', -4 ) === 0 )
1018 - );
1019 - }
1020 -
1021 - /**
1022 901 * We do not need any extra credentials if we have gotten this far,
1023 902 * so let's install the plugin.
1024 903 *
1025 904 * @since 3.04.02
@@ -1024,19 +903,12 @@
1024 903 *
1025 904 * @since 3.04.02
1026 905 */
1027 906 protected static function install_addon() {
1028 - require_once ABSPATH . 'wp-admin/includes/class-wp-upgrader.php';
907 + require_once( ABSPATH . 'wp-admin/includes/class-wp-upgrader.php' );
1029 908
1030 - $download_url = self::get_current_plugin();
909 + $download_url = FrmAppHelper::get_param( 'plugin', '', 'post', 'esc_url_raw' );
1031 910
1032 - if ( ! self::url_is_allowed( $download_url ) ) {
1033 - return array(
1034 - 'message' => 'Plugin URL is not valid',
1035 - 'success' => false,
1036 - );
1037 - }
1038 -
1039 911 // Create the plugin upgrader with our custom skin.
1040 912 $installer = new Plugin_Upgrader( new FrmInstallerSkin() );
1041 913 $installer->install( $download_url );
1042 914
@@ -1043,9 +915,9 @@
1043 915 // Flush the cache and return the newly installed plugin basename.
1044 916 wp_cache_flush();
1045 917
1046 918 $plugin = $installer->plugin_info();
1047 - if ( ! $plugin ) {
919 + if ( empty( $plugin ) ) {
1048 920 return array(
1049 921 'message' => 'Plugin was not installed. ' . $installer->result,
1050 922 'success' => false,
1051 923 );
@@ -1054,60 +926,27 @@
1054 926 }
1055 927
1056 928 /**
1057 929 * @since 3.06.03
1058 - *
1059 - * @return void
1060 930 */
1061 931 public static function ajax_activate_addon() {
1062 932
1063 933 self::install_addon_permissions();
1064 934
1065 - FrmAppHelper::set_current_screen_and_hook_suffix();
935 + // Set the current screen to avoid undefined notices.
936 + global $hook_suffix;
937 + set_current_screen();
1066 938
1067 939 $plugin = FrmAppHelper::get_param( 'plugin', '', 'post', 'sanitize_text_field' );
1068 940 self::maybe_activate_addon( $plugin );
1069 941
1070 - echo json_encode( self::get_addon_activation_response() );
942 + // Send back a response.
943 + echo json_encode( __( 'Your plugin has been activated. Please reload the page to see more options.', 'formidable' ) );
1071 944 wp_die();
1072 945 }
1073 946
1074 947 /**
1075 - * @return array
1076 - */
1077 - private static function get_addon_activation_response() {
1078 - $activating_page = self::get_activating_page();
1079 -
1080 - $response = array(
1081 - 'message' => __( 'Your plugin has been activated. Would you like to save and reload the page now?', 'formidable' ),
1082 - 'saveAndReload' => $activating_page,
1083 - );
1084 -
1085 - return $response;
1086 - }
1087 -
1088 - /**
1089 - * Return a string that reflects the page from which the addon is being activated on,
1090 - * if it is from settings or form builder, otherwise return empty string.
1091 - *
1092 - * @return string
1093 - */
1094 - private static function get_activating_page() {
1095 - $referer = FrmAppHelper::get_server_value( 'HTTP_REFERER' );
1096 - if ( false !== strpos( $referer, 'frm_action=settings' ) ) {
1097 - return 'settings';
1098 - }
1099 -
1100 - if ( false !== strpos( $referer, 'frm_action=edit' ) ) {
1101 - return 'form_builder';
1102 - }
1103 -
1104 - return '';
1105 - }
1106 -
1107 - /**
1108 948 * @since 3.04.02
1109 - *
1110 949 * @param string $installed The plugin folder name with file name
1111 950 */
1112 951 protected static function maybe_activate_addon( $installed ) {
1113 952 if ( ! $installed ) {
@@ -1113,9 +952,9 @@
1113 952 if ( ! $installed ) {
1114 953 return;
1115 954 }
1116 955
1117 - $activate = self::activate_plugin( $installed );
956 + $activate = activate_plugin( $installed );
1118 957 if ( is_wp_error( $activate ) ) {
1119 958 // Ignore the invalid header message that shows with nested plugins.
1120 959 if ( $activate->get_error_code() !== 'no_plugin_header' ) {
1121 960 if ( wp_doing_ajax() ) {
@@ -1133,15 +972,13 @@
1133 972 /**
1134 973 * Run security checks before installing
1135 974 *
1136 975 * @since 3.04.02
1137 - *
1138 - * @return void
1139 976 */
1140 977 protected static function install_addon_permissions() {
1141 978 check_ajax_referer( 'frm_ajax', 'nonce' );
1142 979
1143 - if ( ! current_user_can( 'activate_plugins' ) || ! self::get_current_plugin() ) {
980 + if ( ! current_user_can( 'activate_plugins' ) || ! isset( $_POST['plugin'] ) ) {
1144 981 echo json_encode( true );
1145 982 wp_die();
1146 983 }
1147 984 }
@@ -1147,10 +984,8 @@
1147 984 }
1148 985
1149 986 /**
1150 987 * @since 4.08
1151 - *
1152 - * @return string
1153 988 */
1154 989 public static function connect_link() {
1155 990 $auth = get_option( 'frm_connect_token' );
1156 991 if ( empty( $auth ) ) {
@@ -1199,9 +1034,11 @@
1199 1034 *
1200 1035 * @since 4.08
1201 1036 */
1202 1037 public static function install_addon_api() {
1203 - self::$plugin = FrmAppHelper::get_param( 'file_url', '', 'request', 'esc_url_raw' );
1038 + // Sanitize when it's used to prevent double sanitizing.
1039 + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput
1040 + $_POST['plugin'] = isset( $_REQUEST['file_url'] ) ? $_REQUEST['file_url'] : ''; // Set for later use
1204 1041
1205 1042 $error = esc_html__( 'Could not install an upgrade. Please download from formidableforms.com and install manually.', 'formidable' );
1206 1043
1207 1044 // Delete so cannot replay.
@@ -1207,9 +1044,9 @@
1207 1044 // Delete so cannot replay.
1208 1045 delete_option( 'frm_connect_token' );
1209 1046
1210 1047 // It's already installed and active.
1211 - $active = self::activate_plugin( 'formidable-pro/formidable-pro.php', false, false, true );
1048 + $active = activate_plugin( 'formidable-pro/formidable-pro.php', false, false, true );
1212 1049 if ( is_wp_error( $active ) ) {
1213 1050 // Download plugin now.
1214 1051 $response = self::download_and_activate();
1215 1052 if ( is_array( $response ) && isset( $response['success'] ) ) {
@@ -1220,9 +1057,9 @@
1220 1057 // If empty license, save it now.
1221 1058 if ( empty( self::get_pro_license() ) && function_exists( 'load_formidable_pro' ) ) {
1222 1059 load_formidable_pro();
1223 1060 $license = stripslashes( FrmAppHelper::get_param( 'key', '', 'request', 'sanitize_text_field' ) );
1224 - if ( ! $license ) {
1061 + if ( empty( $license ) ) {
1225 1062 return array(
1226 1063 'success' => false,
1227 1064 'error' => 'That site does not have a valid license key.',
1228 1065 );
@@ -1260,9 +1097,8 @@
1260 1097 /**
1261 1098 * Render a conditional action button for an add on
1262 1099 *
1263 1100 * @since 4.09.01
1264 - *
1265 1101 * @param array $addon
1266 1102 * @param string|false $license_type
1267 1103 * @param string $plan_required
1268 1104 * @param string $upgrade_link
@@ -1276,12 +1112,8 @@
1276 1112 }
1277 1113
1278 1114 /**
1279 1115 * @since 4.09.01
1280 - *
1281 - * @param array|false $addon
1282 - *
1283 - * @return void
1284 1116 */
1285 1117 protected static function addon_upgrade_link( $addon, $upgrade_link ) {
1286 1118 if ( $addon ) {
1287 1119 $upgrade_link .= '&utm_content=' . $addon['slug'];
@@ -1291,9 +1123,9 @@
1291 1123 // Solutions will go to a separate page.
1292 1124 $upgrade_link = FrmAppHelper::admin_upgrade_link( 'addons', $addon['link'] );
1293 1125 }
1294 1126 ?>
1295 - <a class="install-now button frm-button-secondary frm-button-sm" href="<?php echo esc_url( $upgrade_link ); ?>" target="_blank" rel="noopener" aria-label="<?php esc_attr_e( 'Upgrade Now', 'formidable' ); ?>">
1127 + <a class="install-now button button-secondary frm-button-secondary" href="<?php echo esc_url( $upgrade_link ); ?>" target="_blank" rel="noopener" aria-label="<?php esc_attr_e( 'Upgrade Now', 'formidable' ); ?>">
1296 1128 <?php esc_html_e( 'Upgrade Now', 'formidable' ); ?>
1297 1129 </a>
1298 1130 <?php
1299 1131 }
@@ -1299,30 +1131,22 @@
1299 1131 }
1300 1132
1301 1133 /**
1302 1134 * @since 3.04.02
1303 - *
1304 - * @return void
1305 1135 */
1306 1136 public static function ajax_install_addon() {
1307 1137 self::install_addon_permissions();
1308 1138
1309 - $result = self::download_and_activate();
1310 - if ( isset( $result['success'] ) && ! $result['success'] ) {
1311 - echo json_encode( $result );
1312 - wp_die();
1313 - }
1139 + self::download_and_activate();
1314 1140
1315 - echo json_encode( self::get_addon_activation_response() );
1141 + // Send back a response.
1142 + echo json_encode( __( 'Your plugin has been installed. Please reload the page to see more options.', 'formidable' ) );
1316 1143 wp_die();
1317 1144 }
1318 1145
1319 1146 /**
1320 1147 * @since 4.06.02
1321 - *
1322 1148 * @deprecated 4.09.01
1323 - *
1324 - * @return void
1325 1149 */
1326 1150 public static function ajax_multiple_addons() {
1327 1151 FrmDeprecated::ajax_multiple_addons();
1328 1152 }
@@ -1369,14 +1193,10 @@
1369 1193 }
1370 1194
1371 1195 /**
1372 1196 * @since 3.04.03
1373 - *
1374 1197 * @deprecated 3.06
1375 - *
1376 1198 * @codeCoverageIgnore
1377 - *
1378 - * @return void
1379 1199 */
1380 1200 public static function reset_cached_addons( $license = '' ) {
1381 1201 FrmDeprecated::reset_cached_addons( $license );
1382 1202 }
@@ -1410,12 +1230,9 @@
1410 1230 }
1411 1231
1412 1232 /**
1413 1233 * @deprecated 3.04.03
1414 - *
1415 1234 * @codeCoverageIgnore
1416 - *
1417 - * @return void
1418 1235 */
1419 1236 public static function get_licenses() {
1420 1237 FrmDeprecated::get_licenses();
1421 1238 }