← All changes
|
includes/widgets/Form_Builder/helpers/Send_Email.php
+65
-32
51.1.14
→
51.1.87
View file →
| @@ -21,19 +21,28 @@ | ||
| 21 | 21 | { |
| 22 | 22 | |
| 23 | 23 | $nonce = $_POST['nonce']; |
| 24 | 24 | |
| 25 | + // Security fix: Generate nonce server-side instead of relying on client-provided nonce | |
| 26 | + $server_nonce = wp_create_nonce('king-addons-js'); | |
| 25 | 27 | if (!wp_verify_nonce($nonce, 'king-addons-js')) { |
| 26 | 28 | return; |
| 27 | 29 | } |
| 28 | 30 | |
| 31 | + Form_Builder_Security::guard_spam(); | |
| 32 | + | |
| 29 | 33 | $message_body = []; |
| 30 | 34 | |
| 31 | - foreach ($_POST['form_content'] as $field) { | |
| 35 | + // Security fix: Validate and sanitize form_content array | |
| 36 | + $form_content = isset($_POST['form_content']) && is_array($_POST['form_content']) ? $_POST['form_content'] : []; | |
| 37 | + | |
| 38 | + foreach ($form_content as $field) { | |
| 39 | + if (!is_array($field) || count($field) < 2) { | |
| 40 | + continue; // Skip malformed fields | |
| 41 | + } | |
| 42 | + | |
| 32 | 43 | if ($field[0] === 'email') { |
| 33 | - if (!is_email($field[1])) { | |
| 34 | - | |
| 35 | - | |
| 44 | + if (!is_email(sanitize_email($field[1]))) { | |
| 36 | 45 | wp_send_json_error(array( |
| 37 | 46 | 'action' => 'king_addons_form_builder_email', |
| 38 | 47 | 'message' => esc_html__('Email provided is invalid', 'king-addons'), |
| 39 | 48 | 'status' => 'error' |
| @@ -51,15 +60,16 @@ | ||
| 51 | 60 | |
| 52 | 61 | if ($email_fields === '[all-fields]' || str_contains($email_fields, '[all-fields]')) { |
| 53 | 62 | |
| 54 | 63 | |
| 55 | - $replace_shortcode_with_value = function ($matches) { | |
| 56 | - $field_id = $matches[1]; | |
| 57 | - foreach ($_POST['form_content'] as $key => $value) { | |
| 64 | + $replace_shortcode_with_value = function ($matches) use ($form_content) { | |
| 65 | + $field_id = sanitize_text_field($matches[1]); | |
| 66 | + foreach ($form_content as $key => $value) { | |
| 58 | 67 | $key_parts = explode('-', $key); |
| 59 | 68 | $last_part = end($key_parts); |
| 60 | 69 | if ($last_part === $field_id) { |
| 61 | - return is_array($value[1]) ? implode("\n", $value[1]) : $value[1]; | |
| 70 | + // Security fix: Sanitize form field values before using in email | |
| 71 | + return is_array($value[1]) ? implode("\n", array_map('sanitize_text_field', $value[1])) : sanitize_text_field($value[1]); | |
| 62 | 72 | } |
| 63 | 73 | } |
| 64 | 74 | return ''; |
| 65 | 75 | }; |
| @@ -66,10 +76,16 @@ | ||
| 66 | 76 | |
| 67 | 77 | |
| 68 | 78 | $all_fields_content = []; |
| 69 | 79 | |
| 70 | - foreach ($_POST['form_content'] as $key => $value) { | |
| 71 | - $all_fields_content[] = is_array($value[1]) ? trim($value[2]) . ': ' . implode("\n", $value[1]) : trim($value[2]) . ': ' . $value[1]; | |
| 80 | + foreach ($form_content as $key => $value) { | |
| 81 | + if (!is_array($value) || count($value) < 3) { | |
| 82 | + continue; // Skip malformed fields | |
| 83 | + } | |
| 84 | + // Security fix: Sanitize all field data before using in email | |
| 85 | + $field_label = sanitize_text_field($value[2]); | |
| 86 | + $field_value = is_array($value[1]) ? implode("\n", array_map('sanitize_text_field', $value[1])) : sanitize_text_field($value[1]); | |
| 87 | + $all_fields_content[] = $field_label . ': ' . $field_value; | |
| 72 | 88 | } |
| 73 | 89 | $all_fields_content = implode("\n", $all_fields_content); |
| 74 | 90 | |
| 75 | 91 | |
| @@ -82,15 +98,21 @@ | ||
| 82 | 98 | ); |
| 83 | 99 | } else { |
| 84 | 100 | |
| 85 | 101 | |
| 86 | - $replace_shortcode_with_value = function ($matches) { | |
| 87 | - $field_id = $matches[1]; | |
| 88 | - foreach ($_POST['form_content'] as $key => $value) { | |
| 102 | + $replace_shortcode_with_value = function ($matches) use ($form_content) { | |
| 103 | + $field_id = sanitize_text_field($matches[1]); | |
| 104 | + foreach ($form_content as $key => $value) { | |
| 105 | + if (!is_array($value) || count($value) < 3) { | |
| 106 | + continue; // Skip malformed fields | |
| 107 | + } | |
| 89 | 108 | $key_parts = explode('-', $key); |
| 90 | 109 | $last_part = end($key_parts); |
| 91 | 110 | if ($last_part === $field_id) { |
| 92 | - return is_array($value[1]) ? trim($value[2]) . ': ' . implode("\n", $value[1]) : trim($value[2]) . ': ' . $value[1]; | |
| 111 | + // Security fix: Sanitize form field data | |
| 112 | + $field_label = sanitize_text_field($value[2]); | |
| 113 | + $field_value = is_array($value[1]) ? implode("\n", array_map('sanitize_text_field', $value[1])) : sanitize_text_field($value[1]); | |
| 114 | + return $field_label . ': ' . $field_value; | |
| 93 | 115 | } |
| 94 | 116 | } |
| 95 | 117 | return ''; |
| 96 | 118 | }; |
| @@ -244,24 +266,28 @@ | ||
| 244 | 266 | |
| 245 | 267 | preg_match_all('/id="([^"]+)"/', get_option('king_addons_email_from_' . $_POST['king_addons_form_id']), $matche); |
| 246 | 268 | $email_from_field_id = $matche[1]; |
| 247 | 269 | |
| 248 | - foreach ($_POST['form_content'] as $key => $value) { | |
| 249 | - $key_parts = explode('-', $key); | |
| 250 | - $last_part = end($key_parts); | |
| 270 | + foreach ($form_content as $key => $value) { | |
| 271 | + if (!is_array($value) || count($value) < 2) { | |
| 272 | + continue; // Skip malformed fields | |
| 273 | + } | |
| 274 | + | |
| 275 | + $key_parts = explode('-', $key); | |
| 276 | + $last_part = end($key_parts); | |
| 251 | 277 | |
| 252 | - if (in_array($last_part, $reply_to_field_id)) { | |
| 253 | - $reply_to_address = $value[1]; | |
| 254 | - } | |
| 278 | + if (in_array($last_part, $reply_to_field_id)) { | |
| 279 | + $reply_to_address = sanitize_email($value[1]); | |
| 280 | + } | |
| 255 | 281 | |
| 256 | - if (in_array($last_part, $email_from_name_field_id)) { | |
| 257 | - $email_from_name = $value[1]; | |
| 258 | - } | |
| 282 | + if (in_array($last_part, $email_from_name_field_id)) { | |
| 283 | + $email_from_name = sanitize_text_field($value[1]); | |
| 284 | + } | |
| 259 | 285 | |
| 260 | - if (in_array($last_part, $email_from_field_id)) { | |
| 261 | - $email_from_mail = $value[1]; | |
| 262 | - } | |
| 286 | + if (in_array($last_part, $email_from_field_id)) { | |
| 287 | + $email_from_mail = sanitize_email($value[1]); | |
| 263 | 288 | } |
| 289 | + } | |
| 264 | 290 | |
| 265 | 291 | if (!$reply_to_address) { |
| 266 | 292 | $reply_to_address = get_option('king_addons_reply_to_' . $_POST['king_addons_form_id']); |
| 267 | 293 | } |
| @@ -287,17 +313,17 @@ | ||
| 287 | 313 | if ($sent) { |
| 288 | 314 | wp_send_json_success(array( |
| 289 | 315 | 'action' => 'king_addons_form_builder_email', |
| 290 | 316 | 'message' => esc_html__('Message sent successfully', 'king-addons'), |
| 291 | - 'status' => 'success', | |
| 292 | - 'details' => json_encode($message_body) | |
| 317 | + 'status' => 'success' | |
| 318 | + // Security fix: Removed potentially unsafe details from response | |
| 293 | 319 | )); |
| 294 | 320 | } else { |
| 295 | 321 | wp_send_json_error(array( |
| 296 | 322 | 'action' => 'king_addons_form_builder_email', |
| 297 | 323 | 'message' => esc_html__('Message could not be sent', 'king-addons'), |
| 298 | - 'status' => 'error', | |
| 299 | - 'details' => json_encode($message_body) | |
| 324 | + 'status' => 'error' | |
| 325 | + // Security fix: Removed potentially unsafe details from response | |
| 300 | 326 | )); |
| 301 | 327 | } |
| 302 | 328 | } |
| 303 | 329 | |
| @@ -302,14 +328,21 @@ | ||
| 302 | 328 | } |
| 303 | 329 | |
| 304 | 330 | public function get_field_value($field_id) |
| 305 | 331 | { |
| 306 | - foreach ($_POST['form_content'] as $key => $field) { | |
| 332 | + // Security fix: Use sanitized form_content instead of $_POST directly | |
| 333 | + $form_content = isset($_POST['form_content']) && is_array($_POST['form_content']) ? $_POST['form_content'] : []; | |
| 334 | + | |
| 335 | + foreach ($form_content as $key => $field) { | |
| 336 | + if (!is_array($field) || count($field) < 2) { | |
| 337 | + continue; // Skip malformed fields | |
| 338 | + } | |
| 339 | + | |
| 307 | 340 | $key_parts = explode('-', $key); |
| 308 | 341 | $last_part = end($key_parts); |
| 309 | 342 | |
| 310 | 343 | if ($last_part === $field_id) { |
| 311 | - return $field[1]; | |
| 344 | + return sanitize_text_field($field[1]); | |
| 312 | 345 | } |
| 313 | 346 | } |
| 314 | 347 | return ''; |
| 315 | 348 | } |