PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.12.8
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.12.8
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
← All changes | inc/abilities/entries/entry-parser.php +9 -6 2.7.0 → 2.12.8 View file →
@@ -28,9 +28,9 @@
28 28 trait Entry_Parser {
29 29 /**
30 30 * Parse a raw entry array into the standard response shape.
31 31 *
32 - * Handles form data decryption, form title lookup,
32 + * Handles form data decoding, form title lookup,
33 33 * submission info building (with IP masking), and user info.
34 34 *
35 35 * @param array<string,mixed> $entry Raw entry from the database.
36 36 * @since 2.5.2
@@ -36,9 +36,9 @@
36 36 * @since 2.5.2
37 37 * @return array<string,mixed> Parsed entry data (without entry_id — caller prepends it).
38 38 */
39 39 protected function parse_entry( array $entry ) {
40 - // Parse form data with decrypted labels.
40 + // Parse form data with decoded labels (submitter-controlled; escape at the sink).
41 41 $form_data = [];
42 42 $excluded_fields = Helper::get_excluded_fields();
43 43 $entry_form_data = $entry['form_data'] ?? [];
44 44
@@ -52,9 +52,9 @@
52 52 }
53 53
54 54 $label_parts = explode( '-lbl-', $field_name );
55 55 $label = isset( $label_parts[1] ) ? explode( '-', $label_parts[1] )[0] : '';
56 - $label = $label ? Helper::decrypt( $label ) : '';
56 + $label = $label ? Helper::decode( $label ) : '';
57 57 $field_block_name = Helper::get_block_name_from_field( $field_name );
58 58
59 59 $form_data[] = [
60 60 'label' => $label,
@@ -86,11 +86,14 @@
86 86 }
87 87 }
88 88
89 89 $submission_info = [
90 - 'user_ip' => $ip,
91 - 'browser_name' => (string) ( $submission_info_raw['browser_name'] ?? '' ),
92 - 'device_name' => (string) ( $submission_info_raw['device_name'] ?? '' ),
90 + 'user_ip' => $ip,
91 + 'browser_name' => (string) ( $submission_info_raw['browser_name'] ?? '' ),
92 + 'device_name' => (string) ( $submission_info_raw['device_name'] ?? '' ),
93 + // Re-sanitize at the exposure boundary in case the stored value
94 + // was written by a future code path that bypasses form-submit.php.
95 + 'submission_url' => esc_url_raw( (string) ( $submission_info_raw['submission_url'] ?? '' ), [ 'http', 'https' ] ),
93 96 ];
94 97
95 98 // Build user info.
96 99 $user_id = Helper::get_integer_value( $entry['user_id'] ?? 0 );