PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.12.8
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.12.8
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
← All changes | modules/gutenberg/dist/blocks/advanced-heading/class-advanced-heading.php +27 -3 0.0.10 → 2.12.8 View file →
@@ -4,8 +4,10 @@
4 4 *
5 5 * @package Sureforms
6 6 */
7 7
8 +use SRFM\Inc\Helper;
9 +
8 10 if ( ! defined( 'ABSPATH' ) ) {
9 11 exit; // Exit if accessed directly.
10 12 }
11 13
@@ -661,10 +663,20 @@
661 663 if ( isset( $attributes['headingWrapper'] ) ) {
662 664 $heading_wrapper = $attributes['headingWrapper'];
663 665 }
664 666
665 - $element = ! empty( $heading_wrapper ) ? $heading_wrapper : 'div';
667 + // Validate tag-name attributes against the editor UI options to prevent
668 + // arbitrary HTML injection in tag-name position (esc_attr() does not strip
669 + // `<`, `>`, spaces or `=`, which is unsafe when echoed as a tag name).
670 + $allowed_wrapper_tags = [ 'div', 'header' ];
671 + $allowed_heading_tags = [ 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'p', 'div' ];
666 672
673 + $element = in_array( $heading_wrapper, $allowed_wrapper_tags, true ) ? $heading_wrapper : 'div';
674 +
675 + $heading_tag = isset( $attributes['headingTag'] ) && in_array( $attributes['headingTag'], $allowed_heading_tags, true )
676 + ? $attributes['headingTag']
677 + : 'h2';
678 +
667 679 $seperator = '';
668 680
669 681 if ( isset( $attributes['separatorStyle'] )
670 682 && 'none' !== $attributes['separatorStyle']
@@ -678,9 +690,9 @@
678 690 $heading_text = 'above-heading' === $attributes['separatorPosition'] ? $seperator : '';
679 691 $attributes['headingId'] = isset( $attributes['headingId'] ) ? "id='{$attributes['headingId']}'" : '';
680 692 $heading_text .= sprintf(
681 693 '<%1$s class="uagb-heading-text" %3$s>%2$s</%1$s>',
682 - esc_attr( $attributes['headingTag'] ),
694 + esc_attr( $heading_tag ),
683 695 $attributes['headingTitle'],
684 696 esc_attr( $attributes['headingId'] )
685 697 );
686 698 $heading_text .= 'below-heading' === $attributes['separatorPosition'] ? $seperator : '';
@@ -698,13 +710,25 @@
698 710 }
699 711
700 712 $conditional_class = apply_filters( 'srfm_conditional_logic_classes', $form_id, $block_id );
701 713
714 + $filter_classes = apply_filters( 'srfm_field_classes', '', [ 'attributes' => $attributes ] );
715 + $field_config = apply_filters(
716 + 'srfm_field_config',
717 + [],
718 + [
719 + 'attributes' => $attributes,
720 + 'blockName' => 'srfm/advanced-heading',
721 + ]
722 + );
723 + $field_config = $field_config ? htmlspecialchars( Helper::get_string_value( wp_json_encode( $field_config, JSON_UNESCAPED_SLASHES | JSON_UNESCAPED_UNICODE ) ), ENT_QUOTES, 'UTF-8' ) : '';
724 +
702 725 $main_classes = [
703 726 'wp-block-uagb-advanced-heading',
704 727 'uagb-block',
705 728 'uagb-block-' . $block_id,
706 729 $conditional_class,
730 + $filter_classes,
707 731 ];
708 732
709 733 if ( isset( $attributes['className'] ) ) {
710 734 $main_classes[] = $attributes['className'];
@@ -711,9 +735,9 @@
711 735 }
712 736
713 737 ob_start();
714 738 ?>
715 - <<?php echo esc_attr( $element ); ?> data-block-id="<?php echo esc_attr( $block_id ); ?>" class="<?php echo esc_attr( implode( ' ', $main_classes ) ); ?>">
739 + <<?php echo esc_attr( $element ); ?> data-block-id="<?php echo esc_attr( $block_id ); ?>" class="<?php echo esc_attr( implode( ' ', $main_classes ) ); ?>" <?php echo ! empty( $field_config ) ? "data-field-config='" . esc_attr( $field_config ) . "'" : ''; ?>>
716 740 <?php
717 741 if ( $attributes['headingDescToggle']
718 742 && 'above-heading' === $attributes['headingDescPosition']
719 743 ) {