| @@ -231,9 +231,9 @@ | ||
| 231 | 231 | } |
| 232 | 232 | |
| 233 | 233 | $label = explode( '-lbl-', $field_name )[1]; |
| 234 | 234 | $label = explode( '-', $label )[0]; |
| 235 | - $field_label = $label ? Helper::decrypt( $label ) : ''; | |
| 235 | + $field_label = $label ? Helper::decode( $label ) : ''; | |
| 236 | 236 | |
| 237 | 237 | $field_block_name = Helper::get_block_name_from_field( $field_name ); |
| 238 | 238 | |
| 239 | 239 | /** |
| @@ -249,9 +249,12 @@ | ||
| 249 | 249 | * @param array $field_data Field data containing: |
| 250 | 250 | * 'value' => mixed The field value |
| 251 | 251 | * 'label' => string The field name/key |
| 252 | 252 | * 'block_name' => string The block type identifier |
| 253 | - * 'processed_label' => string The decrypted human readable label | |
| 253 | + * 'processed_label' => string The human readable label, base64-decoded | |
| 254 | + * out of the submitted field key. Submitter- | |
| 255 | + * controlled and unauthenticated — escape it | |
| 256 | + * for the output context (esc_html() for HTML). | |
| 254 | 257 | */ |
| 255 | 258 | do_action( |
| 256 | 259 | 'srfm_before_processing_all_data_field', |
| 257 | 260 | [ |
| @@ -315,9 +318,10 @@ | ||
| 315 | 318 | |
| 316 | 319 | ?> |
| 317 | 320 | <tr class="field-label"> |
| 318 | 321 | <th style="<?php echo esc_attr( $td_style ); ?>color: #1E293B;background-color: #F1F5F9;"> |
| 319 | - <strong><?php echo wp_kses_post( html_entity_decode( $field_label ) ); ?>:</strong> | |
| 322 | + <?php // The label is decoded from the submitted field key, so it is attacker-controllable — escape it as text, never as markup. ?> | |
| 323 | + <strong><?php echo esc_html( html_entity_decode( $field_label ) ); ?>:</strong> | |
| 320 | 324 | </th> |
| 321 | 325 | </tr> |
| 322 | 326 | <tr class="field-value"> |
| 323 | 327 | <td style="<?php echo esc_attr( $td_style ); ?>color: #475569;"> |