PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / trunk
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More vtrunk
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/helpers/FrmAppHelper.php +39 -12 6.34 → trunk View file →
@@ -28,9 +28,9 @@
28 28 * @since 2.0
29 29 *
30 30 * @var string
31 31 */
32 - public static $plug_version = '6.34';
32 + public static $plug_version = '6.35';
33 33
34 34 /**
35 35 * @var bool
36 36 */
@@ -1369,10 +1369,9 @@
1369 1369 if ( isset( $atts['echo'] ) ) {
1370 1370 unset( $atts['echo'] );
1371 1371 }
1372 1372
1373 - $html_atts = self::array_to_html_params( $atts );
1374 - $icon = trim( str_replace( array( 'frm_icon_font', 'frmfont ' ), '', $class ) );
1373 + $icon = trim( str_replace( array( 'frm_icon_font', 'frmfont ' ), '', $class ) );
1375 1374
1376 1375 // Replace icons that have been removed or renamed.
1377 1376 $deprecated = array(
1378 1377 'frm_clone_solid_icon' => 'frm_clone_icon',
@@ -1384,11 +1383,11 @@
1384 1383 $icon = $deprecated[ $icon ];
1385 1384 $class = str_replace( $icon, $deprecated[ $icon ], $class );
1386 1385 }
1387 1386
1388 - if ( $icon === $class ) {
1389 - $icon = '<i class="' . esc_attr( $class ) . '"' . $html_atts . '></i>';
1390 - } else {
1387 + $is_font_icon = $icon === $class;
1388 +
1389 + if ( ! $is_font_icon ) {
1391 1390 $class = str_contains( $icon, ' ' ) ? ' ' . $icon : '';
1392 1391
1393 1392 if ( str_contains( $icon, ' ' ) ) {
1394 1393 $icon = explode( ' ', $icon );
@@ -1393,18 +1392,46 @@
1393 1392 if ( str_contains( $icon, ' ' ) ) {
1394 1393 $icon = explode( ' ', $icon );
1395 1394 $icon = reset( $icon );
1396 1395 }
1396 + }
1397 1397
1398 - $icon = '<svg class="frmsvg' . esc_attr( $class ) . '"' . $html_atts . '><use href="#' . esc_attr( $icon ) . '" /></svg>';
1399 - }
1398 + if ( $atts ) {
1399 + // A caller passed attributes, so kses still has to decide which of them survive. Its
1400 + // allowlist comes from safe_html() through the frm_striphtml_allowed_tags filter, and
1401 + // add-ons widen it around their own icons, so there is no fixed list to check against.
1402 + $html_atts = self::array_to_html_params( $atts );
1403 + $markup = $is_font_icon
1404 + ? '<i class="' . esc_attr( $class ) . '"' . $html_atts . '></i>'
1405 + : '<svg class="frmsvg' . esc_attr( $class ) . '"' . $html_atts . '><use href="#' . esc_attr( $icon ) . '" /></svg>';
1400 1406
1401 - if ( $echo ) {
1402 - echo self::kses_icon( $icon ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1407 + if ( ! $echo ) {
1408 + return $markup;
1409 + }
1410 +
1411 + echo self::kses_icon( $markup ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1403 1412 return null;
1404 1413 }
1405 1414
1406 - return $icon;
1415 + /**
1416 + * With no attributes from the caller, the tag is nothing but this method's own markup
1417 + * around an escaped class and icon id, so there is nothing left for kses to decide and it
1418 + * can be skipped. Echoing the pieces rather than a finished string keeps that safe to the
1419 + * escaping sniff without an annotation.
1420 + *
1421 + * This is the path the form builder takes for most of the tens of thousands of icons it
1422 + * renders on a large form, and the kses pass was most of what each one cost.
1423 + */
1424 + $callback = function () use ( $is_font_icon, $class, $icon ) {
1425 + if ( $is_font_icon ) {
1426 + echo '<i class="' . esc_attr( $class ) . '"></i>';
1427 + return;
1428 + }
1429 +
1430 + echo '<svg class="frmsvg' . esc_attr( $class ) . '"><use href="#' . esc_attr( $icon ) . '" /></svg>';
1431 + };
1432 +
1433 + return self::clip( $callback, $echo );
1407 1434 }
1408 1435
1409 1436 /**
1410 1437 * Run kses for icons. It needs to add a few filters first in order to preserve some custom style values.
@@ -1631,9 +1658,9 @@
1631 1658
1632 1659 printf(
1633 1660 /* translators: %1$s: Start link HTML, %2$s: CTA text ("upgrading to PRO" by default), %3$s: End link HTML */
1634 1661 esc_html__( 'You\'re using Formidable Forms Lite. To unlock more features consider %1$s%2$s%3$s.', 'formidable' ),
1635 - '<a href="' . esc_url( $upgrade_link ) . '">',
1662 + '<a href="' . esc_url( $upgrade_link ) . '" target="_blank" rel="noopener">',
1636 1663 esc_html( $cta_text ),
1637 1664 '</a>'
1638 1665 );
1639 1666 ?>