PluginProbe
Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls / 6.5.1
Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls v6.5.1
6.5.1 6.5.0 6.4.9 6.4.8 6.4.7 6.4.6 6.4.5 6.4.4 6.4.3 6.4.2 6.4.1 6.4.0 6.3.9 6.3.8 6.3.7 6.3.6 6.3.5 6.3.4 6.3.3 5.6.0 5.6.1 5.6.2 5.6.3 5.6.4 5.6.5 All 154 releases
← All changes | public/class-poll-maker-ays-public.php +616 -123 5.6.5 → 6.5.1 View file →
@@ -79,8 +79,9 @@
79 79 $this->settings = new Poll_Maker_Settings_Actions($this->plugin_name);
80 80 add_shortcode('ays_poll_all', array($this, 'ays_poll_all_generate_shortcode'));
81 81 add_shortcode('ayspoll_results', array($this, 'ays_poll_results_generate_shortcode'));
82 82 add_shortcode('ays_display_polls', array($this, 'ays_generate_display_polls_method'));
83 + add_shortcode('ays_poll_cat', array($this, 'ays_poll_generate_categories_method'));
83 84 }
84 85
85 86 /**
86 87 * Get instance of this class. Singleton pattern.
@@ -113,9 +114,9 @@
113 114 * between the defined hooks and the functions defined in this
114 115 * class.
115 116 */
116 117
117 - wp_enqueue_style( 'ays_poll_font_awesome', POLL_MAKER_AYS_ADMIN_URL . '/css/poll-maker-ays-admin-fonts.css', array(), $this->version, 'all');
118 + wp_enqueue_style( 'ays_poll_font_awesome', esc_url(POLL_MAKER_AYS_ADMIN_URL) . '/css/poll-maker-ays-admin-fonts.css', array(), $this->version, 'all');
118 119
119 120 }
120 121
121 122 public function enqueue_styles_early(){
@@ -140,9 +141,9 @@
140 141 }
141 142
142 143 $ays_is_elementor = $this->ays_is_elementor();
143 144 if ( $ays_is_elementor ) {
144 - wp_enqueue_style( 'ays_poll_font_awesome', POLL_MAKER_AYS_ADMIN_URL . '/css/poll-maker-ays-admin-fonts.css', array(), $this->version, 'all');
145 + wp_enqueue_style( 'ays_poll_font_awesome', esc_url(POLL_MAKER_AYS_ADMIN_URL) . '/css/poll-maker-ays-admin-fonts.css', array(), $this->version, 'all');
145 146 }
146 147 }
147 148
148 149 public function ays_is_elementor(){
@@ -186,20 +187,21 @@
186 187 wp_enqueue_script($this->plugin_name.'-category', plugin_dir_url(__FILE__) . 'js/poll-maker-public-category.js', array('jquery'), $this->version, false);
187 188 wp_enqueue_script( $this->plugin_name . '-autosize', plugin_dir_url(__FILE__) . 'js/poll-maker-autosize.js', array( 'jquery' ), $this->version, false );
188 189 wp_localize_script($this->plugin_name . '-ajax-public', 'poll_maker_ajax_public',
189 190 array(
190 - 'ajax_url' => admin_url('admin-ajax.php'),
191 - 'alreadyVoted' => __( "You have already voted" , "poll-maker" ),
192 - 'day' => __( 'day', "poll-maker" ),
193 - 'days' => __( 'days', "poll-maker" ),
194 - 'hour' => __( 'hour', "poll-maker" ),
195 - 'hours' => __( 'hours', "poll-maker" ),
196 - 'minute' => __( 'minute', "poll-maker" ),
197 - 'minutes' => __( 'minutes', "poll-maker" ),
198 - 'second' => __( 'second', "poll-maker" ),
199 - 'seconds' => __( 'seconds', "poll-maker" ),
200 - 'thank_message' => __( 'Your answer has been successfully sent to the admin. Please wait for the approval.', "poll-maker" ),
201 - 'restart' => __( 'Restart', "poll-maker" ),
191 + 'ajax_url' => admin_url('admin-ajax.php'),
192 + 'nonce' => wp_create_nonce('ays_poll_nonce'),
193 + 'alreadyVoted' =>esc_html__( "You have already voted" , "poll-maker" ),
194 + 'day' =>esc_html__( 'day', "poll-maker" ),
195 + 'days' =>esc_html__( 'days', "poll-maker" ),
196 + 'hour' =>esc_html__( 'hour', "poll-maker" ),
197 + 'hours' =>esc_html__( 'hours', "poll-maker" ),
198 + 'minute' =>esc_html__( 'minute', "poll-maker" ),
199 + 'minutes' =>esc_html__( 'minutes', "poll-maker" ),
200 + 'second' =>esc_html__( 'second', "poll-maker" ),
201 + 'seconds' =>esc_html__( 'seconds', "poll-maker" ),
202 + 'thank_message' =>esc_html__( 'Your answer has been successfully sent to the admin. Please wait for the approval.', "poll-maker" ),
203 + 'restart' =>esc_html__( 'Restart', "poll-maker" ),
202 204 )
203 205 );
204 206 }
205 207
@@ -204,13 +206,131 @@
204 206 }
205 207
206 208 public function show_chart_js() {
207 209 wp_enqueue_script( $this->plugin_name . '-charts-google', plugin_dir_url(__FILE__) . 'js/google-chart.js', array('jquery'), $this->version, true);
210 + }
211 +
212 + // Categories shortcode
213 + public function ays_poll_generate_categories_method($attr) {
214 + ob_start();
215 + global $wpdb;
216 + $id = (isset($attr['id'])) ? absint(intval($attr['id'])) : null;
217 +
218 + if (is_null($id)) {
219 + echo "<p class='wrong_shortcode_text' style='color:red;'>" . __('Wrong shortcode initialized', 'poll-maker') . "</p>";
220 + return false;
221 + }
222 +
223 + $display = ( isset($attr['display']) && $attr['display'] != '' ) ? $attr['display'] : 'all';
224 + $layout = ( isset($attr['layout']) && $attr['layout'] != '' ) ? $attr['layout'] : 'list';
225 + $count = ( isset($attr['count']) && $attr['count'] != '' ) ? absint(intval($attr['count'])) : 5;
226 + $cat_polls_sorting = (isset($attr['sorting']) && $attr['sorting'] != '' ) ? $attr['sorting'] : 'date_asc';
227 +
228 + $style = '';
229 + $conteiner_style = '';
230 + if ($layout == 'grid') {
231 + $conteiner_style = 'display: flex; flex-wrap: wrap;';
232 + $style = 'margin: 5px;';
233 + }
234 +
235 + $category = $this->ays_get_poll_category($id);
236 +
237 + $sql = "SELECT * FROM {$wpdb->prefix}ayspoll_polls WHERE `categories` LIKE '%".$id."%'";
238 +
239 + $content = "";
240 + $random_poll_id = array();
241 + if ($display === 'random') {
242 + $sql .= " ORDER BY RAND() LIMIT ".$count;
243 + }
244 +
245 + $result = '';
246 + if($cat_polls_sorting == 'popular_asc' && $display == 'all'){
247 + $popular_asc_sql = "SELECT p.*
248 + FROM {$wpdb->prefix}ayspoll_reports AS r
249 + RIGHT JOIN {$wpdb->prefix}ayspoll_polls AS p
250 + ON r.poll_id = p.id
251 + WHERE p.categories LIKE '%{$id}%'
252 + GROUP BY p.id
253 + ORDER BY COUNT(answer_id) ASC LIMIT ".$count;
254 + $result = $wpdb->get_results($popular_asc_sql, 'ARRAY_A');
255 + }elseif($cat_polls_sorting == 'popular_desc' && $display == 'all'){
256 + $popular_desc_sql = "SELECT p.id
257 + FROM {$wpdb->prefix}ayspoll_reports AS r
258 + RIGHT JOIN {$wpdb->prefix}ayspoll_polls AS p
259 + ON r.poll_id = p.id
260 + WHERE p.categories LIKE '%{$id}%'
261 + GROUP BY p.id
262 + ORDER BY COUNT(answer_id) DESC LIMIT ".$count;
263 + $result = $wpdb->get_results($popular_desc_sql, 'ARRAY_A');
264 + }else if($cat_polls_sorting == 'date_asc' && $display == 'all'){
265 + $sql = "SELECT * FROM {$wpdb->prefix}ayspoll_polls
266 + WHERE `categories`
267 + LIKE '%".$id."%'
268 + ORDER BY id ASC LIMIT ".$count;
269 + $result = $wpdb->get_results($sql, 'ARRAY_A');
270 + }else if($cat_polls_sorting == 'date_desc' && $display == 'all'){
271 + $sql = "SELECT * FROM {$wpdb->prefix}ayspoll_polls
272 + WHERE `categories`
273 + LIKE '%".$id."%'
274 + ORDER BY id DESC LIMIT ".$count;
275 + $result = $wpdb->get_results($sql, 'ARRAY_A');
276 + }else{
277 + $sql = "SELECT * FROM {$wpdb->prefix}ayspoll_polls
278 + WHERE `categories`
279 + LIKE '%".$id."%'
280 + ORDER BY RAND() LIMIT ".$count;
281 + $result = $wpdb->get_results($sql, 'ARRAY_A');
282 + }
283 +
284 +
285 + $check_poll = false;
286 + $all_poll_count = count($result);
287 + foreach ($result as $val) {
288 + $val = absint(intval($val['id']));
289 + $options = (isset($val['styles']) && $val['styles'] != null) ? json_decode($val['styles'], true) : array();
290 + $check_poll = $this->check_shedule_expired_poll( $val );
291 +
292 + if (!$check_poll) {
293 + continue;
294 + }
295 +
296 + $random_poll_id[] = $val;
297 + }
298 +
299 + $cat_settings_table = esc_sql($wpdb->prefix."ayspoll_settings");
300 + $cat_key_meta = esc_sql('options');
301 + $cat_sql = "SELECT meta_value FROM ".$cat_settings_table." WHERE meta_key = %s";
302 + $ct_sql = $wpdb->get_var(
303 + $wpdb->prepare( $cat_sql, $cat_key_meta)
304 + );
305 +
306 + $cat_options_res = ($ct_sql === false) ? json_encode(array()) : $ct_sql;
307 + $cat_option_res = json_decode($cat_options_res, true);
308 +
309 + if (isset($cat_option_res['show_cat_title']) && $cat_option_res['show_cat_title'] == 'on') {
310 + $content .= "<h2 class='ays-poll-category-title' style='text-align:center;'>
311 + <span style='font-size:3rem;'>". __( "Category", 'poll-maker') .":</span>
312 + <em>". stripslashes($category['title']) ."</em>
313 + </h2>";
314 +
315 + if(isset($category['description']) && $category['description'] != ''){
316 + $content .= "<div class='ays-poll-category-description'>". do_shortcode(stripslashes(wpautop($category['description']))) ."</div>";
317 + }
318 + }
319 +
320 + $content .= "<div class='ays-poll-category-containers' style='".$conteiner_style."'>";
321 + foreach ($random_poll_id as $poll_id) {
322 + $content .= '<div class="ays-poll-main" id="ays-poll-container-'.$poll_id.'" style="'.$style.'">';
323 + $content .= '<div class="ays-poll-category-item">';
324 + $shortcode = '[ays_poll id="'.$poll_id.'"]';
325 + $content .= do_shortcode($shortcode);
326 + $content .= '</div>';
327 + $content .= '</div>';
328 + }
329 + $content .= '</div>';
330 + echo $content;
331 + return str_replace(array("\r\n", "\n", "\r"), '', ob_get_clean());
208 332 }
209 - // public function show_column_chart_js() {
210 - // // wp_enqueue_script( $this->plugin_name . '-column-chart', 'https://www.gstatic.com/charts/loader.js', array('jquery'), $this->version, true);
211 - // wp_enqueue_script( $this->plugin_name . '-column-chart', plugin_dir_url(__FILE__) . 'js/poll-maker-chart-loader.js', array('jquery'), $this->version, true);
212 - // }
213 333
214 334 public function ays_poll_results_generate_shortcode($attr) {
215 335 ob_start();
216 336
@@ -246,9 +366,8 @@
246 366
247 367 $chart_style = false;
248 368 if (isset( $result_option_res['show_result_view']) && ( $result_option_res['show_result_view'] == 'pie_chart' || $result_option_res['show_result_view'] == 'column_chart' )) {
249 369 $this->show_chart_js();
250 - // $this->show_column_chart_js();
251 370 $chart_style = true;
252 371 }
253 372
254 373 if ($polls == null) {
@@ -390,8 +509,33 @@
390 509 }
391 510 else{
392 511 foreach ($poll_answers as $ans_key => $ans_val) {
393 512 $percent = round($one_percent*intval($ans_val['votes']));
513 + $real_votes = 0;
514 + $all_votes_bar = 0;
515 + if($polls['type'] == 'choosing'){
516 + $real_votes = isset($ans_val['votes']) ? intval($ans_val['votes']) : 0;
517 + $fake_votes = isset($ans_val['fake_votes']) ? intval($ans_val['fake_votes']) : 0;
518 + if($poll_fake_votes){
519 + if($fake_votes + $real_votes < 0){
520 + $all_votes_bar += $real_votes;
521 + }
522 + else{
523 + $all_votes_bar += ($real_votes + $fake_votes);
524 + }
525 + }
526 + else{
527 + $all_votes_bar += $real_votes;
528 + }
529 +
530 + if($sum_of_votes > 0){
531 + $percent = round((100*$all_votes_bar)/$sum_of_votes);
532 + }
533 + }
534 + else{
535 + $all_votes_bar = $ans_val['votes'];
536 + }
537 +
394 538 if ($percent == 0) {
395 539 $perc_cont = '';
396 540 }else{
397 541 $perc_cont = $percent.' %';
@@ -411,8 +555,9 @@
411 555 '. $answer_image_box . '
412 556 <div class="ays-poll-answer-text-and-percent-box">
413 557 <div class="answer-title flex-apm">
414 558 <span class="answer-text">'.stripslashes($ans_val['answer']).'</span>
559 + <span class="answer-votes">'.$all_votes_bar.' ('.$percent.'%)</span>
415 560 </div>
416 561 <div class="progress-bar-container">
417 562 <div class="answer-percent-res"
418 563 style="width: '.$percent.'%;
@@ -505,9 +650,9 @@
505 650 $hand_type = '<i class="ays_poll_far ays_poll_fa-thumbs-down far"></i>';
506 651 }
507 652 $content .= '<div class="answer-title flex-apm">
508 653 <span class="answer-text">'.$hand_type.'</span>
509 - <span class="answer-votes">'.$ans_val['votes'].'</span>
654 + <span class="answer-votes">'.$all_votes_bar.' ('.$percent.'%)</span>
510 655 </div>
511 656 <div class="answer-percent" style="width: '.$percent.'%; background-color: '.$polls_options['main_color'].'; color: '.$polls_options['bg_color'].';">'.$perc_cont.'</div>';
512 657 break;
513 658 case 'emoji':
@@ -518,9 +663,9 @@
518 663 $emojy_type = '<i class="ays_poll_far ays_poll_fa-frown far"></i>';
519 664 }
520 665 $content .= '<div class="answer-title flex-apm">
521 666 <span class="answer-text">'.$emojy_type.'</span>
522 - <span class="answer-votes">'.$ans_val['votes'].'</span>
667 + <span class="answer-votes">'.$all_votes_bar.' ('.$percent.'%)</span>
523 668 </div>
524 669 <div class="answer-percent" style="width: '.$percent.'%; background-color: '.$polls_options['main_color'].'; color: '.$polls_options['bg_color'].';">'.$perc_cont.'</div>';
525 670
526 671 break;
@@ -626,13 +771,16 @@
626 771 if (isset($options['published']) && intval($options['published']) === 0) {
627 772 return "";
628 773 }
629 774
630 - $info_form = !empty($options['info_form']) && !empty($options['fields']);
631 - $info_form_title = !empty($options['info_form_title']) ? wp_kses_post(stripslashes($options['info_form_title'])) : "<div>" . __("Please fill out the form:", "poll-maker") . "</div>";
632 - $fields = !empty($options['fields']) ? explode(",", $options['fields']) : array();
633 - $required_fields = !empty($options['required_fields']) ? explode(",", $options['required_fields']) : array();
775 + $form_fields_option = isset($options['fields']) ? $options['fields'] : array();
776 + $form_required_fields_option = isset($options['required_fields']) ? $options['required_fields'] : array();
634 777
778 + $info_form = !empty($options['info_form']) && !empty($form_fields_option);
779 + $info_form_title = !empty($options['info_form_title']) ? wp_kses_post(stripslashes($options['info_form_title'])) : "<div>" .esc_html__("Please fill out the form:", "poll-maker") . "</div>";
780 + $fields = !empty($form_fields_option) && !is_array($form_fields_option) ? explode(",", $form_fields_option) : (is_array($form_fields_option) ? $form_fields_option : array());
781 + $required_fields = !empty($form_required_fields_option) && !is_array($form_required_fields_option) ? explode(",", $form_required_fields_option) : (is_array($form_required_fields_option) ? $form_required_fields_option : array());
782 +
635 783 $is_expired = false;
636 784 $is_start_soon = false;
637 785 $startDate = '';
638 786 $endDate = '';
@@ -719,9 +867,9 @@
719 867 $hide_results = "1";
720 868 if (!empty($options['hide_results_text'])) {
721 869 $hide_results_text = wpautop($options['hide_results_text']);
722 870 } else {
723 - $hide_results_text = __("Thanks for your answer", "poll-maker");
871 + $hide_results_text =esc_html__("Thanks for your answer", "poll-maker");
724 872 }
725 873 } else {
726 874 $hide_results = "0";
727 875 $hide_results_text = "";
@@ -736,9 +884,9 @@
736 884 $redirect_delay = isset($options['poll_every_answer_redirect_delay']) && $options['poll_every_answer_redirect_delay'] != "" ? esc_attr($options['poll_every_answer_redirect_delay']) : 0;
737 885 }
738 886 $redirect_url_href = '';
739 887 $redirect_url_checked = 1;
740 - $redirect_after_vote = "<p class='redirectionAfterVote'>" . __("You will be redirected", "poll-maker") . " " . ($redirect_delay <= 0 ? "" : __("after", "poll-maker") . " <span>" . $redirect_delay . "</span>" . " " . __("seconds", "poll-maker")) . "</p>";
888 + $redirect_after_vote = "<p class='redirectionAfterVote'>" .esc_html__("You will be redirected", "poll-maker") . " " . ($redirect_delay <= 0 ? "" :esc_html__("after", "poll-maker") . " <span>" . $redirect_delay . "</span>" . " " .esc_html__("seconds", "poll-maker")) . "</p>";
741 889 }elseif (isset($options['redirect_users']) && $options['redirect_users'] != 0 && !empty($options['redirect_after_vote_url'])) {
742 890 $redirect_after_vote_url = stripslashes($options['redirect_after_vote_url']);
743 891 $redirect_url_href = '';
744 892 $redirect_users = $options['redirect_users'];
@@ -743,9 +891,9 @@
743 891 $redirect_url_href = '';
744 892 $redirect_users = $options['redirect_users'];
745 893 $redirect_delay = $options['redirect_after_vote_delay'];
746 894 $redirect_url_checked = 0;
747 - $redirect_after_vote = "<p class='redirectionAfterVote'>" . __("You will be redirected", "poll-maker") . " " . ($redirect_delay <= 0 ? "" : __("after", "poll-maker") . " <span>" . $redirect_delay . "</span>" . " " . __("seconds", "poll-maker")) . "</p>";
895 + $redirect_after_vote = "<p class='redirectionAfterVote'>" .esc_html__("You will be redirected", "poll-maker") . " " . ($redirect_delay <= 0 ? "" :esc_html__("after", "poll-maker") . " <span>" . $redirect_delay . "</span>" . " " .esc_html__("seconds", "poll-maker")) . "</p>";
748 896 } else {
749 897 $redirect_after_vote_url = '';
750 898 $redirect_url_href = '';
751 899 $redirect_users = 0;
@@ -766,14 +914,9 @@
766 914 );
767 915
768 916 $bg_color = $options['bg_color'];
769 917 $bg_image = isset($options['bg_image']) && $options['bg_image'] != '' ? esc_url($options['bg_image']): '';
770 - // if ($bg_image != '') {
771 - // if ( !(filter_var($bg_image, FILTER_VALIDATE_URL) && wp_http_validate_url($bg_image)) ) {
772 - // // invalid URL, handle accordingly
773 - // $bg_image = '';
774 - // }
775 - // }
918 +
776 919 if( $bg_image != "" ){
777 920 $check_if_current_image_exists = Poll_Maker_Ays_Admin::ays_poll_check_if_current_image_exists($bg_image);
778 921
779 922 if( !$check_if_current_image_exists ){
@@ -833,9 +976,9 @@
833 976
834 977 $ays_see_result_button = (isset($options['see_res_btn_text']) && $options['see_res_btn_text'] != '') ? stripslashes( esc_attr( $options['see_res_btn_text'] )) : 'See Results';
835 978
836 979 if ($ays_see_result_button === 'See Results') {
837 - $ays_see_result_button_text = __("See Results", "poll-maker");
980 + $ays_see_result_button_text = esc_html__("See Results", "poll-maker");
838 981 }else{
839 982 $ays_see_result_button_text = $ays_see_result_button;
840 983 }
841 984
@@ -1030,9 +1173,9 @@
1030 1173 }
1031 1174
1032 1175 if ($poll_vote_reason) {
1033 1176 $vote_reason = "<div class='ays-poll-vote-reason'>
1034 - <div class='ays-poll-for-reason'>". __("Please add vote reason", "poll-maker")."</div>
1177 + <div class='ays-poll-for-reason'>".esc_html__("Please add vote reason", "poll-maker")."</div>
1035 1178 <div><textarea name='ays-poll-reason-text' id='ays-poll-reason-text'></textarea></div>
1036 1179 </div>";
1037 1180 } else {
1038 1181 $vote_reason = "";
@@ -1095,9 +1238,11 @@
1095 1238 // Buttons border radius
1096 1239 $buttons_border_radius = isset($options['poll_buttons_border_radius']) && $options['poll_buttons_border_radius'] != '' ? esc_attr($options['poll_buttons_border_radius']) . 'px' : '3px';
1097 1240 // Buttons width
1098 1241 $buttons_width = isset($options['poll_buttons_width']) && $options['poll_buttons_width'] != '' ? esc_attr($options['poll_buttons_width']) . 'px' : 'auto';
1099 -
1242 + // Buttons mobile width
1243 + $buttons_mobile_width = isset($options['poll_buttons_mobile_width']) && $options['poll_buttons_mobile_width'] != '' ? esc_attr($options['poll_buttons_mobile_width']) . 'px' : 'auto';
1244 +
1100 1245 // Poll View Type
1101 1246 $answer_view_type_old = isset($options['poll_answer_view_type']) && $options['poll_answer_view_type'] != '' ? esc_attr($options['poll_answer_view_type']) : 'list';
1102 1247 $answer_view_type = isset($poll['view_type']) && $poll['view_type'] != '' ? esc_attr($poll['view_type']) : $answer_view_type_old;
1103 1248
@@ -1137,8 +1282,14 @@
1137 1282
1138 1283 // Poll title font size mobile
1139 1284 $poll_title_font_size_mobile = (isset($options['poll_title_font_size_mobile']) && $options['poll_title_font_size_mobile'] != "") ? absint(intval(esc_attr($options['poll_title_font_size_mobile']))) : "20";
1140 1285
1286 + // Poll title font weight
1287 + $poll_title_font_weight = (isset($options['poll_title_font_weight']) && $options['poll_title_font_weight'] != "") ? esc_attr($options['poll_title_font_weight']) : "normal";
1288 +
1289 + // Poll title font weight mobile
1290 + $poll_title_font_weight_mobile = (isset($options['poll_title_font_weight_mobile']) && $options['poll_title_font_weight_mobile'] != "") ? esc_attr($options['poll_title_font_weight_mobile']) : $poll_title_font_weight;
1291 +
1141 1292 // Poll title alignment
1142 1293 $poll_title_alignment = ( isset($options['poll_title_alignment']) && $options['poll_title_alignment'] != "" ) ? esc_attr($options['poll_title_alignment']) : "center";
1143 1294
1144 1295 // Poll title alignment mobile
@@ -1143,8 +1294,11 @@
1143 1294
1144 1295 // Poll title alignment mobile
1145 1296 $poll_title_alignment_mobile = ( isset($options['poll_title_alignment_mobile']) && $options['poll_title_alignment_mobile'] != "" ) ? esc_attr($options['poll_title_alignment_mobile']) : $poll_title_alignment;
1146 1297
1298 + // Poll title text transform
1299 + $poll_title_text_transform = ( isset($options['poll_title_text_transform']) && $options['poll_title_text_transform'] != "" ) ? esc_attr($options['poll_title_text_transform']) : "none";
1300 +
1147 1301 // ===== Poll text type options start =====
1148 1302 $poll_view_type_text = isset($poll['view_type']) && $poll['view_type'] != "" ? $poll['view_type'] : "short_text";
1149 1303
1150 1304 $poll_text_type_length_enable = (isset($options['poll_text_type_length_enable']) && $options['poll_text_type_length_enable'] == "on") ? true : false;
@@ -1159,9 +1313,9 @@
1159 1313
1160 1314 if($poll_text_type_limit_message && ($poll_text_type_limit_length != "" && intval($poll_text_type_limit_length) != 0)){
1161 1315 $poll_box_for_limit_message = '<div class="ays_quiz_question_text_conteiner">
1162 1316 <div class="ays_quiz_question_text_message">
1163 - <span class="ays_poll_question_text_message_span">'. $poll_text_type_limit_length . '</span> ' . $poll_text_type_limit_type . ' '. __( ' left' , "poll-maker" ) . '
1317 + <span class="ays_poll_question_text_message_span">'. $poll_text_type_limit_length . '</span> ' . $poll_text_type_limit_type . ' '. esc_html__( ' left' , "poll-maker" ) . '
1164 1318 </div>
1165 1319 </div>';
1166 1320 }
1167 1321 $poll_text_type_ready_width = "";
@@ -1203,9 +1357,9 @@
1203 1357 $poll_enable_password_visibility = (isset($options['poll_enable_password_visibility']) && $options['poll_enable_password_visibility'] == 'on') ? true : false;
1204 1358
1205 1359
1206 1360 $password_input_val = isset($_POST['ays_poll_password_val_'. $id ]) && $_POST['ays_poll_password_val_'. $id ] != "" ? stripslashes(esc_attr($_POST['ays_poll_password_val_'. $id ])) : '';
1207 - $poll_password_message = (isset($options['poll_password_message']) && $options['poll_password_message'] != '') ? stripslashes( wpautop( $options['poll_password_message'] ) ) : "<p>" . __( "Please enter password", "poll-maker" ) . "</p>";
1361 + $poll_password_message = (isset($options['poll_password_message']) && $options['poll_password_message'] != '') ? stripslashes( wpautop( $options['poll_password_message'] ) ) : "<p>" .esc_html__( "Please enter password", "poll-maker" ) . "</p>";
1208 1362
1209 1363 $poll_check_only_logged = (isset($options['enable_logged_users']) && $options['enable_logged_users'] == 1 && !is_user_logged_in()) ? true : false;
1210 1364 $poll_password_message_input = "<input type='password' class='ays-poll-password-input' id='ays_poll_password_val_". $id ."' name='ays_poll_password_val_". $id ."' required autocomplete='off'>";
1211 1365
@@ -1210,10 +1364,10 @@
1210 1364 $poll_password_message_input = "<input type='password' class='ays-poll-password-input' id='ays_poll_password_val_". $id ."' name='ays_poll_password_val_". $id ."' required autocomplete='off'>";
1211 1365
1212 1366 if ( $poll_enable_password_visibility ) {
1213 1367 $password_message_with_toggle_class = "ays-poll-password-input-box-visibility";
1214 - $password_message_with_toggle .= "<img src='". POLL_MAKER_AYS_PUBLIC_URL ."/images/poll-maker-eye-visibility-off.svg' class='ays-poll-password-toggle ays-poll-password-toggle-visibility-off'>";
1215 - $password_message_with_toggle .= "<img src='". POLL_MAKER_AYS_PUBLIC_URL ."/images/poll-maker-eye-visibility.svg' class='ays-poll-password-toggle ays-poll-password-toggle-visibility ays_poll_display_none'>";
1368 + $password_message_with_toggle .= "<img src='". esc_url(POLL_MAKER_AYS_PUBLIC_URL) ."/images/poll-maker-eye-visibility-off.svg' class='ays-poll-password-toggle ays-poll-password-toggle-visibility-off'>";
1369 + $password_message_with_toggle .= "<img src='". esc_url(POLL_MAKER_AYS_PUBLIC_URL) ."/images/poll-maker-eye-visibility.svg' class='ays-poll-password-toggle ays-poll-password-toggle-visibility ays_poll_display_none'>";
1216 1370 }
1217 1371
1218 1372
1219 1373 if($poll_enable_password){
@@ -1227,9 +1381,9 @@
1227 1381 ".$poll_password_message_input."
1228 1382 ".$password_message_with_toggle."
1229 1383 </div>
1230 1384 <div class='ays-poll-password-button-box'>
1231 - <input type='submit' class='ays-poll-password-button' name='ays_poll_password_sub_". $id ."' class='ays_poll_password' value='".__( "Submit", "poll-maker" )."'>
1385 + <input type='submit' class='ays-poll-password-button' name='ays_poll_password_sub_". $id ."' class='ays_poll_password' value='". esc_html__( "Submit", "poll-maker" )."'>
1232 1386 </div>
1233 1387 </div>
1234 1388 </div></div></form></div>";
1235 1389 }
@@ -1305,8 +1459,12 @@
1305 1459 width: 55px;
1306 1460 height: 55px;
1307 1461 }
1308 1462
1463 + #".$this_poll_id." span.ayspoll-answers-votes-count-before-voting{
1464 + padding: 10px !important;
1465 + }
1466 +
1309 1467 .$this_poll_id.ays-minimal-theme .apm-choosing input[type=radio]:checked + label, .$this_poll_id.ays-minimal-theme .apm-choosing label.ays_enable_hover:hover{
1310 1468 background-color: " . ($answer_hover_color ? $answer_hover_color : "initial") . " !important;
1311 1469 color: $main_color !important;
1312 1470 border-color: $main_color !important;
@@ -1423,8 +1581,10 @@
1423 1581 padding: " . $buttons_top_bottom_padding . " " . $buttons_left_right_padding . ";
1424 1582 border-radius: " . $buttons_border_radius . ";
1425 1583 color: ". $poll_button_text_color ." !important;
1426 1584 background: ". $button_bg_color ." !important;
1585 + border: none;
1586 + line-height: 12px !important;
1427 1587 }
1428 1588
1429 1589 #".$this_poll_id ." .apm-add-answer input.ays-poll-new-answer-apply-text{
1430 1590 width: 100%;
@@ -1451,9 +1611,9 @@
1451 1611 }
1452 1612
1453 1613 #".$this_poll_id.".box-apm .apm-choosing .ays-poll-each-answer-grid{
1454 1614 width: 100%;
1455 - text-align: center;
1615 + text-align: left;
1456 1616 display: inline-block;
1457 1617 word-break: break-word;
1458 1618 }
1459 1619
@@ -1509,11 +1669,13 @@
1509 1669 }
1510 1670
1511 1671 #".$this_poll_id.".box-apm .apm-title-box div{
1512 1672 font-size: ".$poll_title_font_size."px;
1673 + font-weight: ".$poll_title_font_weight.";
1513 1674 word-break: break-word;
1514 1675 word-wrap: break-word;
1515 1676 text-align: ".$poll_title_alignment.";
1677 + text-transform: ".$poll_title_text_transform.";
1516 1678 }
1517 1679
1518 1680 #".$this_poll_id.".box-apm .ays-poll-answer-container-list{
1519 1681 margin-bottom: ".$poll_answer_margin."px;
@@ -1548,8 +1710,9 @@
1548 1710
1549 1711 #".$this_poll_id.".box-apm .apm-answers .apm-choosing label.ays_label_poll{
1550 1712 ".$answers_box_shadow_content.";
1551 1713 border-radius: ".$poll_answer_border_radius."px;
1714 + position: relative;
1552 1715 }
1553 1716
1554 1717 #".$this_poll_id.".box-apm.text-poll .apm-answers .ays-poll-text-types-inputs{
1555 1718 font-size: ".$poll_answer_font_size.";
@@ -1746,17 +1909,20 @@
1746 1909 #".$this_poll_id.".box-apm {
1747 1910 width: $poll_width_for_mobile;
1748 1911 }
1749 1912
1913 + #".$this_poll_id.".box-apm .ays-poll-btn{
1914 + width: ".$buttons_mobile_width.";
1915 + }
1916 +
1750 1917 .$this_poll_id.box-apm .ays_question p{
1751 1918 font-size: ".$poll_question_font_size_mobile."px;
1752 1919 }";
1753 1920
1754 1921 if ($answers_grid_column_mobile) {
1755 - $content .= "
1756 - .".$this_poll_id." .apm-answers,
1757 - .".$this_poll_id." .ays_poll_grid_view_container {
1758 - flex-direction: column;
1922 + $content .= "
1923 + .".$this_poll_id." .apm-answers .apm-rating i.ays_poll_fa-star {
1924 + font-size: 4vw !important;
1759 1925 }
1760 1926 #".$this_poll_id.".box-apm .ays-poll-answer-container-gird{
1761 1927 width: 100%;
1762 1928 }";
@@ -1764,9 +1930,11 @@
1764 1930
1765 1931 $content .= "
1766 1932 #".$this_poll_id.".box-apm .apm-title-box div{
1767 1933 font-size: ".$poll_title_font_size_mobile."px;
1934 + font-weight: ".$poll_title_font_weight_mobile.";
1768 1935 text-align: ".$poll_title_alignment_mobile.";
1936 + text-transform: ".$poll_title_text_transform.";
1769 1937 word-break: break-word;
1770 1938 word-wrap: break-word;
1771 1939 }
1772 1940
@@ -1903,9 +2071,9 @@
1903 2071 if ($endDate_atr > 0) {
1904 2072 $show_timer .= '<p class="show_timer_countdown" data-timer_countdown="'.$endDate_atr.'"></p>';
1905 2073 }
1906 2074 }else if ($show_timer_type == 'enddate') {
1907 - $show_timer .= '<p class="show_timer_countdown">'.__('This Poll is active until ', "poll-maker").gmdate('jS \of F Y H:i:s', intval($endDate)).'</p>';
2075 + $show_timer .= '<p class="show_timer_countdown">'. esc_html__('This Poll is active until ', "poll-maker").gmdate('jS \of F Y H:i:s', intval($endDate)).'</p>';
1908 2076 }
1909 2077 $show_timer .= "</div>";
1910 2078 }
1911 2079 }elseif ($activeDateCheck && $activeActiveDateCheck && $is_start_soon) {
@@ -1913,9 +2081,9 @@
1913 2081 $show_timer .= "<div class='ays_poll_show_timer'>";
1914 2082 if ($show_timer_type == 'countdown') {
1915 2083 $show_timer .= '<p class="show_timer_countdown" data-timer_countdown="'.$startDate_atr.'"></p>';
1916 2084 }else if ($show_timer_type == 'enddate') {
1917 - $show_timer .= '<p class="show_timer_countdown">'.__('This Poll will start ', "poll-maker").gmdate('jS \of F Y H:i:s', intval($startDate)).'</p>';
2085 + $show_timer .= '<p class="show_timer_countdown">'. esc_html__('This Poll will start ', "poll-maker").gmdate('jS \of F Y H:i:s', intval($startDate)).'</p>';
1918 2086 }
1919 2087 $show_timer .= "</div>";
1920 2088 }
1921 2089 }
@@ -1923,9 +2091,9 @@
1923 2091 $show_cd_and_author = "<div class='ays_poll_cb_and_a'>";
1924 2092 if($show_create_date){
1925 2093 $poll_create_date = (isset($options['create_date']) && $options['create_date'] != '') ? $options['create_date'] : "0000-00-00 00:00:00";
1926 2094 if(Poll_Maker_Ays_Admin::validateDate($poll_create_date)){
1927 - $show_cd_and_author .= "<span>".__("Created on", "poll-maker")." </span><strong><time>".date("F d, Y", strtotime($poll_create_date))."</time></strong>";
2095 + $show_cd_and_author .= "<span>". esc_html__("Created on", "poll-maker")." </span><strong><time>".date("F d, Y", strtotime($poll_create_date))."</time></strong>";
1928 2096 }else{
1929 2097 $show_cd_and_author .= "";
1930 2098 }
1931 2099 }
@@ -1946,11 +2114,11 @@
1946 2114 }
1947 2115 $image = get_avatar($user_id, 32);
1948 2116 if(isset( $author['name'] ) && $author['name'] !== "Unknown"){
1949 2117 if($show_create_date){
1950 - $text = __("By", "poll-maker");
2118 + $text =esc_html__("By", "poll-maker");
1951 2119 }else{
1952 - $text = __("Created by", "poll-maker");
2120 + $text =esc_html__("Created by", "poll-maker");
1953 2121 }
1954 2122 $show_cd_and_author .= "<span> ".$text." </span>".$image."<strong>".$author['name']."</strong>";
1955 2123 }else{
1956 2124 $show_cd_and_author .= "";
@@ -1958,8 +2126,13 @@
1958 2126 }
1959 2127
1960 2128 $show_cd_and_author .= "</div>";
1961 2129
2130 + // Show votes count per answers before voting
2131 + $options['show_votes_before_voting'] = isset($options['show_votes_before_voting']) ? $options['show_votes_before_voting'] : 'off';
2132 + $show_votes_before_voting = (isset($options['show_votes_before_voting']) && $options['show_votes_before_voting'] == 'on') ? true : false;
2133 + $show_votes_before_voting_by = (isset($options['show_votes_before_voting_by']) && $options['show_votes_before_voting_by'] != '') ? $options['show_votes_before_voting_by'] : 'by_count';
2134 +
1962 2135 $poll_login_form = "";
1963 2136 if($show_login_form){
1964 2137 $args = array(
1965 2138 'echo' => false,
@@ -1976,9 +2149,9 @@
1976 2149 $user_first_name = (isset( $poll_user_information['user_first_name'] ) && $poll_user_information['user_first_name'] != "") ? $poll_user_information['user_first_name'] : '';
1977 2150 $user_last_name = (isset( $poll_user_information['user_last_name'] ) && $poll_user_information['user_last_name'] != "") ? $poll_user_information['user_last_name'] : '';
1978 2151 $creation_date = (isset( $poll['styles']['create_date'] ) && $poll['styles']['create_date'] != '') ? $poll['styles']['create_date'] : '';
1979 2152
1980 - $current_poll_author = __( "Unknown", "poll-maker" );
2153 + $current_poll_author = esc_html__( "Unknown", "poll-maker" );
1981 2154 if( !empty($options['author']) ){
1982 2155 if( !is_array($options['author']) ){
1983 2156 $options['author'] = json_decode($options['author'], true);
1984 2157 }
@@ -1991,8 +2164,9 @@
1991 2164 }
1992 2165 }
1993 2166
1994 2167 $user_nickname = '';
2168 + $user_first_name = '';
1995 2169 $user_display_name = '';
1996 2170 $user_wordpress_email = '';
1997 2171 $user_wordpress_roles = '';
1998 2172 $user_wordpress_website = '';
@@ -2001,8 +2175,9 @@
2001 2175 if($user_id != 0){
2002 2176 $usermeta = get_user_meta( $user_id );
2003 2177 if($usermeta !== null){
2004 2178 $user_nickname = (isset($usermeta['nickname'][0]) && sanitize_text_field( $usermeta['nickname'][0] != '') ) ? sanitize_text_field( $usermeta['nickname'][0] ) : '';
2179 + $user_first_name = (isset($usermeta['first_name'][0]) && sanitize_text_field( $usermeta['first_name'][0] != '') ) ? sanitize_text_field( $usermeta['first_name'][0] ) : '';
2005 2180 }
2006 2181
2007 2182 $current_user_data = get_userdata( $user_id );
2008 2183 if ( ! is_null( $current_user_data ) && $current_user_data ) {
@@ -2020,9 +2195,9 @@
2020 2195
2021 2196 $user_wordpress_website_url = ( isset( $current_user_data->user_url ) && ! empty( $current_user_data->user_url ) ) ? sanitize_url($current_user_data->user_url) : "";
2022 2197
2023 2198 if( !empty( $user_wordpress_website_url ) ){
2024 - $user_wordpress_website = "<a href='". esc_url( $user_wordpress_website_url ) ."' target='_blank' class='ays-poll-user-website-link-a-tag'>". __( "Website", "poll-maker" ) ."</a>";
2199 + $user_wordpress_website = "<a href='". esc_url( $user_wordpress_website_url ) ."' target='_blank' class='ays-poll-user-website-link-a-tag'>".esc_html__( "Website", "poll-maker" ) ."</a>";
2025 2200 }
2026 2201 }
2027 2202 }
2028 2203
@@ -2107,9 +2282,9 @@
2107 2282 }
2108 2283 if (!$is_expired) {
2109 2284 //CHECK IF ENABLED ONLY LOGGED IN USERS OPTION
2110 2285 if (isset($options['enable_logged_users']) && $options['enable_logged_users'] == 1 && !is_user_logged_in()) {
2111 - $logged_users_message = isset($options['enable_logged_users_message']) && $options['enable_logged_users_message'] != '' ? $this->ays_autoembed(stripslashes($options['enable_logged_users_message'])) : "<p>" . __('You must sign in for voting.', "poll-maker") . "</p>"; // smbo
2286 + $logged_users_message = isset($options['enable_logged_users_message']) && $options['enable_logged_users_message'] != '' ? $this->ays_autoembed(stripslashes($options['enable_logged_users_message'])) : "<p>" .esc_html__('You must sign in for voting.', "poll-maker") . "</p>"; // smbo
2112 2287
2113 2288 $content .= "<div class='apm-need-sign-in'>".$logged_users_message."</div>";
2114 2289
2115 2290 if($logged_users_message !== null){
@@ -2123,9 +2298,9 @@
2123 2298 // Users role Aro start
2124 2299 global $wp_roles;
2125 2300 $user = wp_get_current_user();
2126 2301 $users_roles = $wp_roles->role_names;
2127 - $message = (isset($options['restriction_pass_message']) && $options['restriction_pass_message'] != '') ? stripslashes($options['restriction_pass_message']) : ("<p>" . __('You not have permissions for voting.', "poll-maker") . "</p>");
2302 + $message = (isset($options['restriction_pass_message']) && $options['restriction_pass_message'] != '') ? stripslashes($options['restriction_pass_message']) : ("<p>" .esc_html__('You not have permissions for voting.', "poll-maker") . "</p>");
2128 2303 $users_role = (isset($options['users_role']) && $options['users_role'] != '') ? $options['users_role'] : '';
2129 2304 $users_role = json_decode($users_role);
2130 2305 if(!empty($users_role)){
2131 2306 if (is_array($users_role)) {
@@ -2238,9 +2413,9 @@
2238 2413 $multiple_select = 'multiple';
2239 2414 $allow_multivote_answer = 'on';
2240 2415 $poll_multivote_min_count = (isset($options['multivote_answer_min_count']) && $options['multivote_answer_min_count'] != '') ? absint(intval($options['multivote_answer_min_count'])) : '1';
2241 2416 $poll_multivote_min_count_content = "<input type='hidden' id='ays_poll_multivote_min_count' data-allow='true' value='".$poll_multivote_min_count."'/>";
2242 - $poll_multivote_message_content = "<div class='ays-poll-multivote-message add_answer_for_grid'>".__("Min votes count should be" , "poll-maker")." ".$poll_multivote_min_count."</div>";
2417 + $poll_multivote_message_content = "<div class='ays-poll-multivote-message add_answer_for_grid'>". esc_html__("Min votes count should be" , "poll-maker")." ".$poll_multivote_min_count."</div>";
2243 2418 }else{
2244 2419 $multiple_select = '';
2245 2420 $allow_multivote_answer = '';
2246 2421 }
@@ -2269,9 +2444,11 @@
2269 2444 }
2270 2445 }else{
2271 2446 $answer_icon_class = '';
2272 2447 }
2273 -
2448 +
2449 + $poll_answer_votes = null;
2450 + $poll_answer_votes_sum = null;
2274 2451 $content .= "<div class='apm-answers $without_vote ".$answers_container."'>";
2275 2452 switch ( $poll['type'] ) {
2276 2453 case 'choosing':
2277 2454 $pol_answer_view_type = isset($poll['styles']['poll_answer_view_type']) && $poll['styles']['poll_answer_view_type'] != "" ? esc_attr($poll['styles']['poll_answer_view_type']) : "list";
@@ -2286,8 +2463,26 @@
2286 2463 $numbering_type_arr = array();
2287 2464 if($answers_count){
2288 2465 $numbering_type_arr = $this->ays_answer_numbering($show_answers_numbering , $answers_count);
2289 2466 }
2467 +
2468 + $poll_answer_percentages = array();
2469 + $poll_answer_votes = array();
2470 + foreach ( $poll['answers'] as $index => $answer ) {
2471 +
2472 + $poll_answer_votes[$answer['id']] = intval( $answer['votes'] );
2473 + }
2474 +
2475 + $poll_answer_votes_sum = array_sum( $poll_answer_votes );
2476 + $poll_answer_percentages = array();
2477 + foreach ( $poll_answer_votes as $index => $answer_vote_count ) {
2478 + if( $poll_answer_votes_sum != 0 ){
2479 + $poll_answer_percentages[$index] = round( ( $answer_vote_count * 100 ) / $poll_answer_votes_sum, 1);
2480 + }else{
2481 + $poll_answer_percentages[$index] = 0;
2482 + }
2483 + }
2484 +
2290 2485 if($poll_allow_multivote){
2291 2486 $content .= "<input type='hidden' id='multivot_answer_count' value='".$multivote_answer_count."'/>";
2292 2487 $content .= $poll_multivote_min_count_content;
2293 2488 }
@@ -2309,8 +2504,29 @@
2309 2504 if ($poll_view_more_button_count - 1 < $index) {
2310 2505 $answer_style_class = 'ays_poll_display_none';
2311 2506 }
2312 2507 }
2508 +
2509 + $show_votes_before_voting_display_none = "";
2510 + if( !$show_votes_before_voting ){
2511 + $show_votes_before_voting_display_none = "display:none;";
2512 + }
2513 + $opacity_bg_color_svbv = $poll['view_type'] == 'grid' ? 0.6 : 0.3;
2514 + $show_votes_before_voting_color = $this->rgb2hex( $text_color );
2515 + $show_votes_before_voting_color = $this->hex2rgba( $show_votes_before_voting_color, $opacity_bg_color_svbv );
2516 +
2517 + $show_votes_before_voting_display = "style='text-shadow: 0px 0px 5px " . $bg_color . ";'";
2518 + $show_votes_before_voting_display_width = "";
2519 + if( !$show_votes_before_voting ){
2520 + $show_votes_before_voting_display = "style='{$show_votes_before_voting_display_none}text-shadow: 0px 0px 5px " . $bg_color . ";'";
2521 + $show_votes_before_voting_display_width = "style='{$show_votes_before_voting_display_none}text-shadow: 0px 0px 5px " . $bg_color . ";'";
2522 + }
2523 +
2524 + if( $poll['view_type'] == 'grid' ){
2525 + $show_votes_before_voting_display = "style='{$show_votes_before_voting_display_none}justify-content:center;font-weight:900;text-shadow: 0px 0px 5px " . $bg_color . ";'";
2526 + $show_votes_before_voting_display_width = "style='{$show_votes_before_voting_display_none}text-shadow: 0px 0px 5px " . $bg_color . ";'";
2527 + }
2528 +
2313 2529 $pol_answer_view_type_show = 'ays_poll_list_view_item';
2314 2530 $pol_answer_view_type_image = 'ays-poll-each-image-list';
2315 2531 $pol_answer_view_type_cont = 'ays-poll-answer-container-list';
2316 2532 $pol_answer_view_type_label_cont = 'ays-poll-answer-container-label-list';
@@ -2337,8 +2553,22 @@
2337 2553 $pol_answer_view_type_text_show = 'ays-poll-each-answer-list';
2338 2554
2339 2555 $poll_class_for_answer_label_text = "ays_poll_label_text_with_padding";
2340 2556 }
2557 +
2558 + $answer_votes_count_before_voting = "";
2559 + switch ( $show_votes_before_voting_by ) {
2560 + case 'by_percentage':
2561 + $answer_votes_count_before_voting = $poll_answer_percentages[$answer['id']] . "%";
2562 + break;
2563 + default:
2564 + $real_votes = isset($answer['votes']) && $answer['votes'] != "" ? intval( $answer['votes'] ) : 0;
2565 +
2566 + $answer_votes_count_before_voting = $real_votes;
2567 +
2568 + break;
2569 + }
2570 +
2341 2571 $content .= "
2342 2572 <div class='apm-choosing answer-$this_poll_id ". $answer_style_class ." ays-poll-field ".$pol_answer_view_type_cont."' >
2343 2573 <input type=".$poll_multivote_checkbox." name='answer' id='radio-$index-$this_poll_id' value='{$answer['id']}' {$autocomplete_attr}>
2344 2574 <label
@@ -2346,9 +2576,16 @@
2346 2576 class='ays_label_poll ".$answers_sound_class." ".$redirect_after_submit." ".$disable_answer_hover." ays_label_font_size ".$answer_icon_class." ".$poll_class_for_answer_label." ".$pol_answer_view_type_label_cont."'
2347 2577 data-answers-url='".(isset($answer['redirect']) && is_string($answer['redirect']) ? esc_url($answer['redirect']) : '')."'
2348 2578 >".$poll_answer_image_show." <p style='".$poll_added_style."' class='ays-poll-answers'><span class='".$pol_answer_view_type_text_show."'>"
2349 2579 . $numbering_type . esc_attr(stripcslashes($answer['answer'])) .
2350 - "</span></p></label>
2580 + "</span></p>";
2581 +
2582 + $content .= "<span class='ayspoll-answers-votes-count-before-voting' ". $show_votes_before_voting_display .">". $answer_votes_count_before_voting ."</span>
2583 + <span class='ayspoll-answers-votes-count-before-voting-width' ". $show_votes_before_voting_display_width .">
2584 + <span style='width: ". $poll_answer_percentages[$answer['id']] ."%; background-color:" . $show_votes_before_voting_color . ";'></span>
2585 + </span>";
2586 +
2587 + $content .= " </label>
2351 2588 </div>";
2352 2589 }
2353 2590 }
2354 2591 }
@@ -2355,9 +2592,9 @@
2355 2592 $add_answer_for_grid = isset($poll['view_type']) && $poll['view_type'] == 'grid' ? 'add_answer_for_grid' : '';
2356 2593 if ($poll_allow_answer && $with_vote) {
2357 2594 $content .= "
2358 2595 <div class='apm-choosing answer-$this_poll_id ".$this_poll_id."_addAnswer apm-add-answer ".$add_answer_for_grid."'>
2359 - <input type='text' placeholder='" . __("Other - please specify", "poll-maker") . "' class='ays-poll-new-answer-apply-text' name='ays_poll_new_answer'>
2596 + <input type='text' placeholder='" .esc_html__("Other - please specify", "poll-maker") . "' class='ays-poll-new-answer-apply-text' name='ays_poll_new_answer'>
2360 2597 </div>
2361 2598 ";
2362 2599 $allow_multi_vote_for_other = isset($options["poll_allow_multivote"]) && $options["poll_allow_multivote"] == "on" ? true : false;
2363 2600 if(!$allow_multi_vote_for_other){
@@ -2362,9 +2599,9 @@
2362 2599 $allow_multi_vote_for_other = isset($options["poll_allow_multivote"]) && $options["poll_allow_multivote"] == "on" ? true : false;
2363 2600 if(!$allow_multi_vote_for_other){
2364 2601 $content .= "
2365 2602 <div class='ays-poll-add-answer-note ays-poll-add-answer-note-enable'>
2366 - <div class='ays-poll-add-answer-note-text'><img src='".POLL_MAKER_AYS_ADMIN_URL."/images/icons/other-answer-note.svg' >".__( "If 'Other' is filled, checked answers are ignored.", "poll-maker")."</div>
2603 + <div class='ays-poll-add-answer-note-text'><img src='".esc_url(POLL_MAKER_AYS_ADMIN_URL)."/images/icons/other-answer-note.svg' >". esc_html__( "If 'Other' is filled, checked answers are ignored.", "poll-maker")."</div>
2367 2604 </div>
2368 2605 ";
2369 2606 }
2370 2607 }
@@ -2454,9 +2691,9 @@
2454 2691
2455 2692 if ($view_more_button_flag) {
2456 2693 $content .= '
2457 2694 <div class="ays-poll-view-more-button-box">
2458 - <input type="button" class="btn ays-poll-btn ays-poll-view-more-button" value="'. __( "View more", "poll-maker" ) .'">
2695 + <input type="button" class="btn ays-poll-btn ays-poll-view-more-button" value="'.esc_html__( "View more", "poll-maker" ) .'">
2459 2696 </div>';
2460 2697 }
2461 2698
2462 2699 $content .= "</div>";
@@ -2469,9 +2706,9 @@
2469 2706 $content .= "</div>";
2470 2707 if ($info_form) {
2471 2708 $this->fields_placeholders = $this->ays_set_poll_fields_placeholders_texts();
2472 2709 $content .= "\n
2473 - <div class='apm-info-form' data-text='" . __("Send", "poll-maker") . "' style='display: none;'>
2710 + <div class='apm-info-form' data-text='" .esc_html__("Send", "poll-maker") . "' style='display: none;'>
2474 2711 $info_form_title
2475 2712 <div class='amp-info-form-input-box'>
2476 2713 ";
2477 2714 foreach ( $fields as $f ) {
@@ -2505,12 +2742,12 @@
2505 2742 }
2506 2743 $content .= "</div></div>";
2507 2744 }
2508 2745 } else {
2509 - $content .= "<div class='ays-poll-limitation'>" . (isset($options['limitation_message']) && $options['limitation_message'] != '' ? stripslashes($options['limitation_message']) : ("<p>" . __("You have already voted.", "poll-maker") . "</p>")) . "</div>";
2746 + $content .= "<div class='ays-poll-limitation'>" . (isset($options['limitation_message']) && $options['limitation_message'] != '' ? stripslashes($options['limitation_message']) : ("<p>" .esc_html__("You have already voted.", "poll-maker") . "</p>")) . "</div>";
2510 2747 if (isset($options['redirect_url']) && $options['redirect_url'] != '' && isset($options['redirection_delay']) && $options['redirection_delay'] != 0) {
2511 2748 $content .= "<div class='apm-redirection apm-redirection-$this_poll_id'>
2512 - <p data-id='$this_poll_id' data-href='" . stripslashes($options['redirect_url']) . "' data-delay='{$options['redirection_delay']}'>" . __('Redirecting after', "poll-maker")
2749 + <p data-id='$this_poll_id' data-href='" . stripslashes($options['redirect_url']) . "' data-delay='{$options['redirection_delay']}'>" .esc_html__('Redirecting after', "poll-maker")
2513 2750 . " <b>{$this->secondsToWords($options['redirection_delay'])}</b>
2514 2751 </p>
2515 2752 </div>";
2516 2753 }
@@ -2558,9 +2795,9 @@
2558 2795
2559 2796 $ays_vote_button = (isset($options['btn_text']) && $options['btn_text'] != '') ? stripslashes($options['btn_text']) : 'Vote';
2560 2797
2561 2798 if ($ays_vote_button === 'Vote') {
2562 - $ays_vote_button_text = __("Vote", "poll-maker");
2799 + $ays_vote_button_text = esc_html__("Vote", "poll-maker");
2563 2800 }else{
2564 2801 $ays_vote_button_text = $ays_vote_button;
2565 2802 }
2566 2803
@@ -2583,9 +2820,9 @@
2583 2820
2584 2821 $poll_block_preview_message = "";
2585 2822 if( $is_elementor_exists || $is_editor_exists ){
2586 2823 $poll_block_preview_message = '
2587 - <span class="ays_poll_small_hint_text ays_poll_preview_mode_hint">'. esc_attr( __( "You're in the preview mode. Note: All elements work correctly on the front end." , "poll-maker") ) .'</span>';
2824 + <span class="ays_poll_small_hint_text ays_poll_preview_mode_hint">'. esc_attr(esc_html__( "You're in the preview mode. Note: All elements work correctly on the front end." , "poll-maker") ) .'</span>';
2588 2825 }
2589 2826
2590 2827 $content .= $poll_block_preview_message;
2591 2828 $content .= $result_message;
@@ -2590,13 +2827,13 @@
2590 2827 $content .= $poll_block_preview_message;
2591 2828 $content .= $result_message;
2592 2829 $content .= $redirect_after_vote;
2593 2830 } elseif ($is_start_soon) {
2594 - $poll_is_start_message = isset($options['active_date_message_soon']) ? stripslashes($options['active_date_message_soon']) : "<p>" . __('The poll will be available soon.', "poll-maker") . "</p>";
2831 + $poll_is_start_message = isset($options['active_date_message_soon']) ? stripslashes($options['active_date_message_soon']) : "<p>" .esc_html__('The poll will be available soon.', "poll-maker") . "</p>";
2595 2832 $content .= "<div class='apm_expired_poll'>".$poll_is_start_message."</div>";
2596 2833
2597 2834 } else {
2598 - $expired_poll_message = isset($options['active_date_message']) ? stripslashes($options['active_date_message']) : "<p>" . __('The poll has expired.', "poll-maker") . "</p>";
2835 + $expired_poll_message = isset($options['active_date_message']) ? stripslashes($options['active_date_message']) : "<p>" .esc_html__('The poll has expired.', "poll-maker") . "</p>";
2599 2836 $content .= "<div class='apm_expired_poll'>$expired_poll_message</div>";
2600 2837
2601 2838 if ($show_res_btn_sch) {
2602 2839 $content .= $see_result_button;
@@ -2679,9 +2916,9 @@
2679 2916 $polls_pool = $this->ays_get_polls_pool($new_res);
2680 2917
2681 2918 $ays_next_button = (isset($cat_opt['next_text']) && $cat_opt['next_text'] != '') ? stripslashes($cat_opt['next_text']) : 'Next';
2682 2919 if ($ays_next_button === 'Next') {
2683 - $ays_next_button_text = __("Next", "poll-maker");
2920 + $ays_next_button_text = esc_html__("Next", "poll-maker");
2684 2921 } else {
2685 2922 $ays_next_button_text = $ays_next_button;
2686 2923 }
2687 2924
@@ -2686,9 +2923,9 @@
2686 2923 }
2687 2924
2688 2925 $ays_previous_button = (isset($cat_opt['previous_text']) && $cat_opt['previous_text'] != '') ? stripslashes($cat_opt['previous_text']) : 'Previous';
2689 2926 if ($ays_previous_button === 'Previous') {
2690 - $ays_previous_button_text = __("Previous", "poll-maker");
2927 + $ays_previous_button_text = esc_html__("Previous", "poll-maker");
2691 2928 }else{
2692 2929 $ays_previous_button_text = $ays_previous_button;
2693 2930 }
2694 2931
@@ -2797,9 +3034,11 @@
2797 3034 return $poll;
2798 3035 }
2799 3036
2800 3037 private static function get_user_ip() {
2801 - $ipaddress = '';
3038 +
3039 + $ipaddress = false;
3040 +
2802 3041 if (getenv('HTTP_CLIENT_IP')) {
2803 3042 $ipaddress = getenv('HTTP_CLIENT_IP');
2804 3043 } else if (getenv('HTTP_X_FORWARDED_FOR')) {
2805 3044 $ipaddress = getenv('HTTP_X_FORWARDED_FOR');
@@ -2808,15 +3047,20 @@
2808 3047 } else if (getenv('HTTP_FORWARDED_FOR')) {
2809 3048 $ipaddress = getenv('HTTP_FORWARDED_FOR');
2810 3049 } else if (getenv('HTTP_FORWARDED')) {
2811 3050 $ipaddress = getenv('HTTP_FORWARDED');
2812 - } else if (getenv('REMOTE_ADDR')) {
2813 - $ipaddress = getenv('REMOTE_ADDR');
2814 - } else {
2815 - $ipaddress = 'UNKNOWN';
2816 3051 }
2817 3052
2818 - return $ipaddress;
3053 + if ( $ipaddress !== false && filter_var( $ipaddress, FILTER_VALIDATE_IP ) !== false ) {
3054 + return $ipaddress;
3055 + }
3056 +
3057 + $remote_address = getenv('REMOTE_ADDR');
3058 + if ( $remote_address !== false && filter_var( $remote_address, FILTER_VALIDATE_IP ) !== false ) {
3059 + return $remote_address;
3060 + }
3061 +
3062 + return 'UNKNOWN';
2819 3063 }
2820 3064
2821 3065 public static function get_user_ip_validated(){
2822 3066 $headers_to_check = array(
@@ -2854,27 +3098,27 @@
2854 3098
2855 3099 /*** get the days ***/
2856 3100 $days = (int)($seconds / (3600 * 24));
2857 3101 if ($days > 0) {
2858 - $ret .= "$days " . __( 'days', "poll-maker" ) . ' ';
3102 + $ret .= "$days " .esc_html__( 'days', "poll-maker" ) . ' ';
2859 3103 }
2860 3104
2861 3105 /*** get the hours ***/
2862 3106 $hours = (int)(($seconds / 3600) % 24);
2863 3107 if ($hours > 0) {
2864 - $ret .= "$hours " . __( 'hours', "poll-maker" ) . ' ';
3108 + $ret .= "$hours " .esc_html__( 'hours', "poll-maker" ) . ' ';
2865 3109 }
2866 3110
2867 3111 /*** get the minutes ***/
2868 3112 $minutes = (int)(($seconds / 60) % 60);
2869 3113 if ($minutes > 0) {
2870 - $ret .= "$minutes " . __( 'minutes', "poll-maker" ) . ' ';
3114 + $ret .= "$minutes " .esc_html__( 'minutes', "poll-maker" ) . ' ';
2871 3115 }
2872 3116
2873 3117 /*** get the seconds ***/
2874 3118 $seconds = (int)(($seconds) % 60);
2875 3119 if ($seconds > 0) {
2876 - $ret .= "$seconds " . __( 'seconds', "poll-maker" );
3120 + $ret .= "$seconds " .esc_html__( 'seconds', "poll-maker" );
2877 3121 }
2878 3122
2879 3123 return $ret;
2880 3124 }
@@ -2900,8 +3144,28 @@
2900 3144
2901 3145 return $result;
2902 3146 }
2903 3147
3148 + public static function get_poll_category_by_ids($ids){
3149 + global $wpdb;
3150 +
3151 + $ids = array_map('intval', explode(',', $ids));
3152 + $ids = array_filter($ids);
3153 +
3154 + if (empty($ids)) {
3155 + return [];
3156 + }
3157 +
3158 + $ids_sql = implode(',', $ids);
3159 +
3160 + $sql = "SELECT *
3161 + FROM {$wpdb->prefix}ayspoll_categories
3162 + WHERE id IN ($ids_sql)
3163 + ORDER BY FIELD(id, $ids_sql)";
3164 +
3165 + return $wpdb->get_results($sql, ARRAY_A);
3166 + }
3167 +
2904 3168 public function get_poll_status($id) {
2905 3169 global $wpdb;
2906 3170 $poll_id = absint(intval($id));
2907 3171 $poll_table = $wpdb->prefix . 'ayspoll_polls';
@@ -2920,18 +3184,22 @@
2920 3184 }
2921 3185 }
2922 3186
2923 3187 public function ays_poll_get_user_information() {
2924 - if (is_user_logged_in()) {
2925 - $output = json_encode(wp_get_current_user());
2926 - } else {
2927 - $output = null;
3188 + if ( ! check_ajax_referer( 'ays_poll_nonce', '_ajax_nonce', false ) ) {
3189 + wp_send_json_error( array( 'message' => 'Invalid request' ), 403 );
2928 3190 }
3191 + if ( ! is_user_logged_in() ) {
3192 + wp_send_json_error( array( 'message' => 'User not logged in' ), 401 );
3193 + }
2929 3194
2930 - ob_end_clean();
2931 - $ob_get_clean = ob_get_clean();
2932 - echo $output;
2933 - wp_die();
3195 + $user = wp_get_current_user();
3196 +
3197 + wp_send_json_success( array(
3198 + 'display_name' => $user->display_name,
3199 + 'user_email' => $user->user_email,
3200 +
3201 + ) );
2934 3202 }
2935 3203
2936 3204 public function ays_finish_poll() {
2937 3205 global $wpdb;
@@ -3006,8 +3274,22 @@
3006 3274 $poll_answers_count = isset($poll['answers']) ? count($poll['answers']) : 0;
3007 3275 $added_answer_id = array();
3008 3276
3009 3277 $poll_title = (isset($poll['title']) && $poll['title'] != '') ? stripslashes( sanitize_text_field( $poll['title'] ) ) : '';
3278 +
3279 + // Poll category title
3280 + $poll_category_title = "";
3281 +
3282 + $poll_cats = isset( $poll['categories'] ) ? trim( $poll['categories'], ',' ) : '';
3283 + $poll_category_ids = $poll_cats !== '' ? sanitize_text_field( $poll_cats ) : '';
3284 +
3285 + if ( $poll_category_ids != '' ) {
3286 + $categories = self::get_poll_category_by_ids( $poll_category_ids );
3287 + $category_names = wp_list_pluck( $categories, 'title' );
3288 +
3289 + $poll_category_title = implode( ', ', $category_names );
3290 + }
3291 +
3010 3292 $poll_vote_reason_text = "";
3011 3293 $poll_vote_reason = false;
3012 3294 $show_answers_numbering = (isset($options['show_answers_numbering']) && sanitize_text_field( $options['show_answers_numbering'] ) != '') ? sanitize_text_field( $options['show_answers_numbering'] ) : 'none';
3013 3295 if (isset($options['poll_vote_reason']) && $options['poll_vote_reason'] == "on" && isset($_POST['ays-poll-reason-text'])) {
@@ -3214,9 +3496,14 @@
3214 3496 $user_last_name = (isset( $poll_user_information['user_last_name'] ) && $poll_user_information['user_last_name'] != "") ? $poll_user_information['user_last_name'] : '';
3215 3497 $creation_date = (isset( $poll['styles']['create_date'] ) && $poll['styles']['create_date'] != '') ? $poll['styles']['create_date'] : '';
3216 3498
3217 3499
3218 - $current_poll_author = __( "Unknown", "poll-maker" );
3500 + $current_poll_author = esc_html__( "Unknown", "poll-maker" );
3501 + $current_poll_author_email = '';
3502 + $current_poll_author_nickname = '';
3503 + $current_poll_author_display_name = '';
3504 + $current_poll_author_website_url = '';
3505 + $current_poll_author_registered = '';
3219 3506 if( !empty($options['author']) ){
3220 3507 if( !is_array($options['author']) ){
3221 3508 $options['author'] = json_decode($options['author'], true);
3222 3509 }
@@ -3225,14 +3512,40 @@
3225 3512
3226 3513 $current_poll_user_data = get_userdata( $poll_current_author );
3227 3514 if ( ! is_null( $current_poll_user_data ) && $current_poll_user_data ) {
3228 3515 $current_poll_author = ( isset( $current_poll_user_data->data->display_name ) && $current_poll_user_data->data->display_name != '' ) ? sanitize_text_field( $current_poll_user_data->data->display_name ) : "";
3516 + $current_poll_author_email = ( isset( $current_poll_user_data->data->user_email ) && $current_poll_user_data->data->user_email != '' ) ? sanitize_text_field( $current_poll_user_data->data->user_email ) : "";
3517 + $current_poll_author_nickname = ( isset( $current_poll_user_data->data->user_nicename ) && $current_poll_user_data->data->user_nicename != '' ) ? sanitize_text_field( $current_poll_user_data->data->user_nicename ) : "";
3518 + $current_poll_author_display_name = ( isset( $current_poll_user_data->data->display_name ) && $current_poll_user_data->data->display_name != '' ) ? sanitize_text_field( $current_poll_user_data->data->display_name ) : "";
3519 + $current_poll_author_website_url = ( isset( $current_poll_user_data->data->user_url ) && $current_poll_user_data->data->user_url != '' ) ? sanitize_text_field( $current_poll_user_data->data->user_url ) : "";
3520 + $current_poll_author_registered = ( isset( $current_poll_user_data->data->user_registered ) && $current_poll_user_data->data->user_registered != '' ) ? sanitize_text_field( $current_poll_user_data->data->user_registered ) : "";
3229 3521 }
3230 3522 }
3231 3523
3524 + // Get Current date
3232 3525 $poll_current_date = date_i18n( 'M d, Y', strtotime( sanitize_text_field( $_REQUEST['end_date'] ) ) );
3233 3526
3527 + // Get Current time
3528 + $poll_current_time = date_i18n( get_option( 'time_format' ), strtotime( sanitize_text_field( $_REQUEST['end_date'] ) ) );
3529 +
3530 + // Get Current day
3531 + $poll_current_day = date_i18n( 'l', strtotime( sanitize_text_field( $_REQUEST['end_date'] ) ) );
3532 +
3533 + // Get Current month
3534 + $poll_current_month = date_i18n( 'F', strtotime( sanitize_text_field( $_REQUEST['end_date'] ) ) );
3535 +
3536 + // Get Post Title
3537 + $post_id = url_to_postid( $_POST['_wp_http_referer'] );
3538 + $post_title = get_the_title( $post_id );
3539 + $get_site_title = get_bloginfo('name');
3540 + $get_site_description = get_bloginfo('description');
3541 +
3542 + // WP home page url
3543 + $home_main_url = home_url();
3544 + $home_page_url = '<a href="'. $home_main_url .'" target="_blank">'. $home_main_url .'</a>';
3545 +
3234 3546 $user_nickname = '';
3547 + $user_first_name = '';
3235 3548 $user_display_name = '';
3236 3549 $user_wordpress_email = '';
3237 3550 $user_wordpress_roles = '';
3238 3551 $user_wordpress_website = '';
@@ -3237,12 +3550,46 @@
3237 3550 $user_wordpress_roles = '';
3238 3551 $user_wordpress_website = '';
3239 3552 $user_ip_address = '';
3240 3553 $user_id = get_current_user_id();
3241 - if($user_id != 0){
3554 + $user_data = wp_get_current_user();
3555 + $super_admin_email = get_option('admin_email');
3556 +
3557 + $post_author = get_post_field( 'post_author', $post_id );
3558 + $author_id = get_the_author_meta('ID', $post_author);
3559 + $post_author_email = get_the_author_meta( 'email', $author_id );
3560 + $post_author_display_name = get_the_author_meta( 'display_name', $author_id );
3561 + $post_author_nickname = get_the_author_meta( 'nickname', $author_id );
3562 + $post_author_first_name = get_the_author_meta( 'first_name', $author_id );
3563 + $post_author_last_name = get_the_author_meta( 'last_name', $author_id );
3564 + $post_author_website_url = get_the_author_meta( 'url', $author_id );
3565 +
3566 + $post_author_roles = '';
3567 + $user_registered = '';
3568 + if ( is_user_logged_in() ) {
3569 + $post_author_roles = get_the_author_meta( 'roles', $author_id );
3570 + $user_registered = $user_data->user_registered;
3571 + }
3572 +
3573 + if ( ! empty( $post_author_website_url ) ) {
3574 + $post_author_website_url = '<a href="'. $post_author_website_url .'" target="_blank">'. $post_author_website_url .'</a>';
3575 + }
3576 +
3577 + if ( ! empty( $current_poll_author_website_url ) ) {
3578 + $current_poll_author_website_url = '<a href="'. $current_poll_author_website_url .'" target="_blank">'. $current_poll_author_website_url .'</a>';
3579 + }
3580 +
3581 + if ( ! empty( $post_author_roles ) && $post_author_roles != "" ) {
3582 + if ( is_array( $post_author_roles ) ) {
3583 + $post_author_roles = implode( ", ", $post_author_roles );
3584 + }
3585 + }
3586 +
3587 + if( $user_id != 0 ){
3242 3588 $usermeta = get_user_meta( $user_id );
3243 3589 if($usermeta !== null){
3244 3590 $user_nickname = (isset($usermeta['nickname'][0]) && sanitize_text_field( $usermeta['nickname'][0] != '') ) ? sanitize_text_field( $usermeta['nickname'][0] ) : '';
3591 + $user_first_name = (isset($usermeta['first_name'][0]) && sanitize_text_field( $usermeta['first_name'][0] != '') ) ? sanitize_text_field( $usermeta['first_name'][0] ) : '';
3245 3592 }
3246 3593
3247 3594 $current_user_data = get_userdata( $user_id );
3248 3595 if ( ! is_null( $current_user_data ) && $current_user_data ) {
@@ -3260,13 +3607,19 @@
3260 3607
3261 3608 $user_wordpress_website_url = ( isset( $current_user_data->user_url ) && ! empty( $current_user_data->user_url ) ) ? sanitize_url($current_user_data->user_url) : "";
3262 3609
3263 3610 if( !empty( $user_wordpress_website_url ) ){
3264 - $user_wordpress_website = "<a href='". esc_url( $user_wordpress_website_url ) ."' target='_blank' class='ays-poll-user-website-link-a-tag'>". __( "Website", "poll-maker" ) ."</a>";
3611 + $user_wordpress_website = "<a href='". esc_url( $user_wordpress_website_url ) ."' target='_blank' class='ays-poll-user-website-link-a-tag'>".esc_html__( "Website", "poll-maker" ) ."</a>";
3265 3612 }
3266 3613 }
3267 3614 }
3268 3615
3616 + if ( is_user_logged_in() ) {
3617 + $current_user_id = get_current_user_id();
3618 + } else {
3619 + $current_user_id = '';
3620 + }
3621 +
3269 3622 $report_table = $wpdb->prefix."ayspoll_reports";
3270 3623 $answ_table = $wpdb->prefix."ayspoll_answers";
3271 3624
3272 3625 $sql = "SELECT COUNT(*)
@@ -3282,36 +3635,104 @@
3282 3635
3283 3636 $ays_protocol = ((!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] != 'off') || $_SERVER['SERVER_PORT'] == 443) ? "https://" : "http://";
3284 3637
3285 3638 $current_poll_page_link = isset( $_REQUEST['ays_poll_curent_page_link'] ) && $_REQUEST['ays_poll_curent_page_link'] != '' ? sanitize_url( $_REQUEST['ays_poll_curent_page_link'] ) : "";
3286 - $current_poll_page_link_html = "<a href='". esc_sql( $current_poll_page_link ) ."' target='_blank' class='ays-poll-curent-page-link-a-tag'>". __( "Poll link", "poll-maker" ) ."</a>";
3639 + $current_poll_page_link_html = "<a href='". esc_sql( $current_poll_page_link ) ."' target='_blank' class='ays-poll-curent-page-link-a-tag'>".esc_html__( "Poll link", "poll-maker" ) ."</a>";
3287 3640
3288 3641 $form_apm_name = (isset($_POST['apm_name']) && $_POST['apm_name'] != "") ? esc_attr($_POST['apm_name']) : "";
3289 3642 $form_apm_email = (isset($_POST['apm_email']) && $_POST['apm_email'] != "") ? esc_attr($_POST['apm_email']) : "";
3290 3643 $form_apm_phone = (isset($_POST['apm_phone']) && $_POST['apm_phone'] != "") ? esc_attr($_POST['apm_phone']) : "";
3291 -
3644 +
3292 3645 $message_data = array(
3293 - 'user_name' => $form_apm_name,
3294 - 'user_email' => $form_apm_email,
3295 - 'user_phone' => $form_apm_phone,
3296 - 'poll_title' => $poll_title,
3297 - 'users_first_name' => $user_first_name,
3298 - 'users_last_name' => $user_last_name,
3299 - 'creation_date' => $creation_date,
3300 - 'current_date' => $poll_current_date,
3301 - 'current_poll_author' => $current_poll_author,
3302 - 'user_nickname' => $user_nickname,
3303 - 'user_display_name' => $user_display_name,
3304 - 'user_wordpress_email' => $user_wordpress_email,
3305 - 'user_wordpress_roles' => $user_wordpress_roles,
3306 - 'poll_pass_count' => $pass_count,
3307 - 'passed_poll_count_per_user' => $passed_poll_count_per_user,
3308 - 'current_poll_page_link' => $current_poll_page_link_html,
3309 - 'user_wordpress_website' => $user_wordpress_website,
3310 - 'user_ip_address' => $user_ip_address,
3646 + 'user_name' => $form_apm_name,
3647 + 'user_email' => $form_apm_email,
3648 + 'user_phone' => $form_apm_phone,
3649 + 'poll_title' => $poll_title,
3650 + 'poll_category_title' => $poll_category_title,
3651 + 'poll_id' => $poll_id,
3652 + 'users_first_name' => $user_first_name,
3653 + 'users_last_name' => $user_last_name,
3654 + 'creation_date' => $creation_date,
3655 + 'current_date' => $poll_current_date,
3656 + 'current_time' => $poll_current_time,
3657 + 'current_day' => $poll_current_day,
3658 + 'current_month' => $poll_current_month,
3659 + 'current_poll_page_link' => $current_poll_page_link_html,
3660 + 'current_poll_author' => $current_poll_author,
3661 + 'current_poll_author_email' => $current_poll_author_email,
3662 + 'current_poll_author_nickname' => $current_poll_author_nickname,
3663 + 'current_poll_author_display_name' => $current_poll_author_display_name,
3664 + 'current_poll_author_website_url' => $current_poll_author_website_url,
3665 + 'current_poll_author_registered' => $current_poll_author_registered,
3666 + 'admin_email' => $super_admin_email,
3667 + 'user_nickname' => $user_nickname,
3668 + 'user_first_name' => $user_first_name,
3669 + 'user_display_name' => $user_display_name,
3670 + 'user_wordpress_email' => $user_wordpress_email,
3671 + 'user_wordpress_roles' => $user_wordpress_roles,
3672 + 'poll_pass_count' => $pass_count,
3673 + 'passed_poll_count_per_user' => $passed_poll_count_per_user,
3674 + 'user_wordpress_website' => $user_wordpress_website,
3675 + 'user_ip_address' => $user_ip_address,
3676 + 'user_id' => $current_user_id,
3677 + 'user_registered' => $user_registered,
3678 + 'post_title' => $post_title,
3679 + 'post_author_email' => $post_author_email,
3680 + 'post_author_display_name' => $post_author_display_name,
3681 + 'post_author_nickname' => $post_author_nickname,
3682 + 'post_author_first_name' => $post_author_first_name,
3683 + 'post_author_last_name' => $post_author_last_name,
3684 + 'post_author_website_url' => $post_author_website_url,
3685 + 'post_author_roles' => $post_author_roles,
3686 + 'post_id' => $post_id,
3687 + 'site_title' => $get_site_title,
3688 + 'site_description' => $get_site_description,
3689 + 'home_page_url' => $home_page_url,
3311 3690 );
3312 3691
3313 3692 $user_ip = esc_sql($user_ips);
3693 +
3694 + // Race condition fix
3695 + $limitusers = isset($poll['styles']['limit_users']) ? intval($poll['styles']['limit_users']) : 0;
3696 +
3697 + if ($limitusers > 0) {
3698 +
3699 + $limit_users_method = isset($poll['styles']['limit_users_method']) ? $poll['styles']['limit_users_method'] : "ip";
3700 +
3701 + switch ($limit_users_method) {
3702 + case 'ip':
3703 + default:
3704 + $wpdb->query("START TRANSACTION");
3705 + $already_voted = $wpdb->get_var($wpdb->prepare(
3706 + "SELECT COUNT(*) FROM {$report_table} WHERE user_ip = %s AND poll_id = %d FOR UPDATE",
3707 + $user_ip,
3708 + $poll_id
3709 + ));
3710 + break;
3711 + case 'cookie':
3712 + $wpdb->query("START TRANSACTION");
3713 + $already_voted = isset($_COOKIE["ays_this_poll_cookie_" . $poll_id]) ? 1 : 0;
3714 + break;
3715 + case 'user':
3716 + $wpdb->query("START TRANSACTION");
3717 + $already_voted = $wpdb->get_var($wpdb->prepare(
3718 + "SELECT COUNT(*) FROM {$report_table} WHERE user_id = %s AND poll_id = %d FOR UPDATE",
3719 + $user_id,
3720 + $poll_id
3721 + ));
3722 + break;
3723 + }
3724 +
3725 + if ($already_voted > 0) {
3726 + $wpdb->query("ROLLBACK");
3727 +
3728 + $res = $this->get_poll_by_id($poll_id);
3729 + $res['voted_status'] = false;
3730 + echo json_encode($res);
3731 + wp_die();
3732 + }
3733 + }
3734 +
3314 3735 $multi_answer_ids = array();
3315 3736 if ((is_array($answer_id) && !empty($answer_id)) && $allow_multi_vote) {
3316 3737 $multi_answer_ids = $answer_id;
3317 3738 $answer_changed_id = $answer_id[0];
@@ -3367,8 +3788,14 @@
3367 3788 '%d', // poll_id
3368 3789 '%s', // multi_answer_ids
3369 3790 )
3370 3791 );
3792 +
3793 + // Race condition fix
3794 + if ($limitusers > 0) {
3795 + $wpdb->query("COMMIT");
3796 + }
3797 +
3371 3798 // $answers = $this->get_answer_by_id($answer_changed_id);
3372 3799 if (!empty($options['notify_email_on'])) {
3373 3800 $notify_admin_email = $options['notify_email'];
3374 3801 $use_answered = '';
@@ -3380,9 +3807,9 @@
3380 3807 $headers .= "Content-Type: text/html; charset=UTF-8\r\n";
3381 3808 $attachment = array();
3382 3809 $mail_text = (
3383 3810 /* translators: 1: user answer variable, 2: poll title variable 3: anchor tag */
3384 - sprintf( __( "Someone's answer %1\$s in your %2\$s poll on %3\$s.", "poll-maker" ),
3811 + sprintf(esc_html__( "Someone's answer %1\$s in your %2\$s poll on %3\$s.", "poll-maker" ),
3385 3812 $use_answered,
3386 3813 '"' . $poll_title . '"',
3387 3814 "<a href='" . home_url() . "' target='_blank'>" . home_url() . "</a>"
3388 3815 ));
@@ -3452,11 +3879,49 @@
3452 3879
3453 3880
3454 3881 $res['styles']['result_message'] = ( isset( $res['styles']['result_message'] ) && $res['styles']['result_message'] != "" ) ? $this->ays_autoembed($this->replace_message_variables($res['styles']['result_message'], $message_data)) : "";
3455 3882 $res['styles']['hide_results_text'] = ( isset( $res['styles']['hide_results_text'] ) && $res['styles']['hide_results_text'] != "" ) ? $this->ays_autoembed($this->replace_message_variables($res['styles']['hide_results_text'], $message_data)) : "";
3456 -
3883 + $sensitive_fields = [
3884 + 'notify_email',
3885 + 'author',
3886 + 'poll_create_author',
3887 + 'mailchimp_list',
3888 + 'users_role'
3889 + ];
3890 + if (!current_user_can('manage_options')) {
3891 + foreach ($sensitive_fields as $field) {
3892 + if (isset($res['styles'][$field]) && $res['styles'][$field] != "") {
3893 + unset($res['styles'][$field]);
3894 + }
3895 + }
3896 + }
3457 3897 $res['styles']['poll_social_buttons_heading'] = ( isset( $res['styles']['poll_social_buttons_heading'] ) && $res['styles']['poll_social_buttons_heading'] != "" ) ? $this->ays_autoembed($res['styles']['poll_social_buttons_heading']) : "";
3458 3898 $res['check_admin_approval'] = $check_admin_approval;
3899 +
3900 + /**
3901 + * Fires after a user successfully submits a vote in Poll Maker.
3902 + *
3903 + * @since 1.0.0
3904 + *
3905 + * @param int $poll_id The poll ID.
3906 + */
3907 + if (has_action('ays_poll_maker_after_vote')) {
3908 + // Collect extra contextual data for hooks
3909 + $user_id = get_current_user_id();
3910 + $data = array_merge(
3911 + (array) $message_data,
3912 + array(
3913 + 'poll_id' => $poll_id,
3914 + 'answer_id' => $answer_id,
3915 + 'user_id' => $user_id,
3916 + )
3917 + );
3918 + do_action(
3919 + 'ays_poll_maker_after_vote',
3920 + $data
3921 + );
3922 + }
3923 +
3459 3924 ob_end_clean();
3460 3925 $ob_get_clean = ob_get_clean();
3461 3926 echo json_encode($res);
3462 3927 wp_die();
@@ -3729,9 +4194,9 @@
3729 4194 $polls_options = $poll['styles'];
3730 4195
3731 4196
3732 4197 // $poll_answer_sorting = isset($polls_options['result_sort_type']) && $polls_options['result_sort_type'] != "none" ? $polls_options['result_sort_type'] : "ASC";
3733 - $ans_sql = "SELECT * FROM ".$answ_table." WHERE poll_id =%d ORDER BY id ASC";
4198 + $ans_sql = "SELECT * FROM ".$answ_table." WHERE poll_id =%d ORDER BY votes DESC";
3734 4199 $poll_answers = $wpdb->get_results(
3735 4200 $wpdb->prepare( $ans_sql, $id),
3736 4201 'ARRAY_A'
3737 4202 );
@@ -3808,22 +4273,26 @@
3808 4273 if($poll_show_avatars && $poll_user_avatars != ""){
3809 4274 $poll_avatars_content = '<div class="ays-user-count">
3810 4275 '.$poll_user_avatars.'
3811 4276 <div class="ays-users-profile-pics">
3812 - <img src="'.POLL_MAKER_AYS_PUBLIC_URL.'/images/more.png" width="24" height="24" class="ays-user-image-more" data-answer-id='.$ans_val["id"].'>
4277 + <img src="'.esc_url(POLL_MAKER_AYS_PUBLIC_URL).'/images/more.png" width="24" height="24" class="ays-user-image-more" data-answer-id='.$ans_val["id"].'>
3813 4278 </div>
3814 4279 </div>';
3815 4280 }
3816 4281 $perc_cont = '';
3817 4282 $percent = round($one_percent*intval($ans_val['votes']));
4283 + $perc_conta_hide_or_no = '';
3818 4284 if($poll_show_answer_perc){
3819 4285 if ($percent == 0) {
3820 4286 $perc_cont = '0 %';
4287 + $perc_conta_hide_or_no = '';
3821 4288 }else{
3822 4289 $perc_cont = $percent.' %';
4290 + $perc_conta_hide_or_no = '('.$percent.'%'.')';
3823 4291 }
3824 4292
3825 4293 }
4294 +
3826 4295 $answer_votes_count = '';
3827 4296 if($poll_show_votes_count){
3828 4297 $answer_votes_count = isset($ans_val['votes']) ? esc_attr($ans_val['votes']) : '';
3829 4298 }
@@ -3840,8 +4309,9 @@
3840 4309
3841 4310 $content .= '<div class="ays-poll-answer-text-and-percent-box">';
3842 4311 $content .= '<div class="answer-title flex-apm">
3843 4312 <span class="answer-text">' . stripslashes($ans_val['answer']) . '</span>
4313 + <span class="answer-votes">'.$answer_votes_count.' '.$perc_conta_hide_or_no.'</span>
3844 4314 </div>
3845 4315 ' . $poll_avatars_content . '
3846 4316 <div class="answer-percent-res" style="width: ' . ($percent == 0 ? '10' : $percent) . '%;
3847 4317 border-radius: 20px;
@@ -3966,8 +4436,24 @@
3966 4436 $content .= "</div>";
3967 4437 return $content;
3968 4438 }
3969 4439
4440 + public function intToRoman($num) {
4441 + $map = array(
4442 + 1000 => 'M', 900 => 'CM', 500 => 'D', 400 => 'CD',
4443 + 100 => 'C', 90 => 'XC', 50 => 'L', 40 => 'XL',
4444 + 10 => 'X', 9 => 'IX', 5 => 'V', 4 => 'IV', 1 => 'I'
4445 + );
4446 + $roman = '';
4447 + foreach ($map as $value => $symbol) {
4448 + while ($num >= $value) {
4449 + $roman .= $symbol;
4450 + $num -= $value;
4451 + }
4452 + }
4453 + return $roman;
4454 + }
4455 +
3970 4456 public function ays_answer_numbering($numbering , $count){
3971 4457 $keyword_arr = array();
3972 4458 switch ($numbering) {
3973 4459 case '1.':
@@ -4013,8 +4499,15 @@
4013 4499 $columns[] = strtolower($value) . ")";
4014 4500 }
4015 4501 $keyword_arr = $columns;
4016 4502 break;
4503 + case 'VI.':
4504 + $columns = array();
4505 + for ($i = 1; $i <= $count; $i++) {
4506 + $columns[] = $this->intToRoman($i) . ".";
4507 + }
4508 + $keyword_arr = $columns;
4509 + break;
4017 4510 default:
4018 4511 break;
4019 4512 }
4020 4513 return $keyword_arr;
@@ -4234,11 +4727,11 @@
4234 4727
4235 4728 $poll_fields_placeholder_phone = (isset($settings_placeholders_texts['poll_fields_placeholder_phone']) && $settings_placeholders_texts['poll_fields_placeholder_phone'] != '') ? stripslashes( esc_attr( $settings_placeholders_texts['poll_fields_placeholder_phone'] ) ) : 'Phone';
4236 4729
4237 4730
4238 - $poll_fields_placeholder_name_text = $poll_fields_placeholder_name === 'Name' ? __('Name', "poll-maker") : $poll_fields_placeholder_name;
4239 - $poll_fields_placeholder_email_text = $poll_fields_placeholder_email === 'Email' ? __('Email', "poll-maker") : $poll_fields_placeholder_email;
4240 - $poll_fields_placeholder_phone_text = $poll_fields_placeholder_phone === 'Phone' ? __('Phone', "poll-maker") : $poll_fields_placeholder_phone;
4731 + $poll_fields_placeholder_name_text = $poll_fields_placeholder_name === 'Name' ?esc_html__('Name', "poll-maker") : $poll_fields_placeholder_name;
4732 + $poll_fields_placeholder_email_text = $poll_fields_placeholder_email === 'Email' ?esc_html__('Email', "poll-maker") : $poll_fields_placeholder_email;
4733 + $poll_fields_placeholder_phone_text = $poll_fields_placeholder_phone === 'Phone' ?esc_html__('Phone', "poll-maker") : $poll_fields_placeholder_phone;
4241 4734
4242 4735
4243 4736 $poll_fields_label_name = (isset($settings_placeholders_texts['poll_fields_label_name']) && $settings_placeholders_texts['poll_fields_label_name'] != '') ? stripslashes( esc_attr( $settings_placeholders_texts['poll_fields_label_name'] ) ) : 'Name';
4244 4737
@@ -4246,11 +4739,11 @@
4246 4739
4247 4740 $poll_fields_label_phone = (isset($settings_placeholders_texts['poll_fields_label_phone']) && $settings_placeholders_texts['poll_fields_label_phone'] != '') ? stripslashes( esc_attr( $settings_placeholders_texts['poll_fields_label_phone'] ) ) : 'Phone';
4248 4741
4249 4742
4250 - $poll_fields_label_name_text = $poll_fields_label_name === 'Name' ? __('Name', "poll-maker") : $poll_fields_label_name;
4251 - $poll_fields_label_email_text = $poll_fields_label_email === 'Email' ? __('Email', "poll-maker") : $poll_fields_label_email;
4252 - $poll_fields_label_phone_text = $poll_fields_label_phone === 'Phone' ? __('Phone', "poll-maker") : $poll_fields_label_phone;
4743 + $poll_fields_label_name_text = $poll_fields_label_name === 'Name' ?esc_html__('Name', "poll-maker") : $poll_fields_label_name;
4744 + $poll_fields_label_email_text = $poll_fields_label_email === 'Email' ?esc_html__('Email', "poll-maker") : $poll_fields_label_email;
4745 + $poll_fields_label_phone_text = $poll_fields_label_phone === 'Phone' ?esc_html__('Phone', "poll-maker") : $poll_fields_label_phone;
4253 4746
4254 4747 $texts = array(
4255 4748 'namePlaceholder' => $poll_fields_placeholder_name_text,
4256 4749 'emailPlaceholder' => $poll_fields_placeholder_email_text,
@@ -4318,5 +4811,5 @@
4318 4811 $id = isset($last_poll_sql['id']) && $last_poll_sql['id'] !== 0 ? absint(intval($last_poll_sql['id'])) : "";
4319 4812
4320 4813 return $id;
4321 4814 }
4322 -}
4815 +}