PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.12.8
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.12.8
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
← All changes | inc/duplicate-form.php +17 -2 2.7.0 → 2.12.8 View file →
@@ -122,9 +122,24 @@
122 122 if ( '_edit_lock' === $meta_key || '_edit_last' === $meta_key ) {
123 123 continue;
124 124 }
125 125
126 + // The view counter belongs to the form that earned it. Cloning it
127 + // would give the copy an impression count with no submissions behind
128 + // it — a permanent 0% conversion rate — and double-count those views
129 + // in the site-wide analytics total.
130 + if ( \SRFM\Inc\Form_Views::META_KEY === $meta_key ) {
131 + continue;
132 + }
133 +
126 134 // Handle unserialized metas (these are already arrays/objects).
135 + // Note: get_post_meta() returns unslashed data, but add_post_meta()
136 + // internally runs wp_unslash() on the value. Without re-slashing,
137 + // backslashes are stripped — corrupting JSON-string metas (e.g.
138 + // _srfm_save_resume, _srfm_conditional_confirmation) whose escaped
139 + // quotes (\") then fail json_decode() in their sanitize callbacks,
140 + // causing those callbacks to wipe the value to an empty string.
141 + // wp_slash() pre-escapes so wp_unslash() restores the original.
127 142 if ( in_array( $meta_key, $unserialized_metas, true ) ) {
128 143 if ( is_array( $meta_values ) && isset( $meta_values[0] ) ) {
129 144 // Ensure the value is a string before unserializing.
130 145 $first_value = $meta_values[0];
@@ -129,15 +144,15 @@
129 144 // Ensure the value is a string before unserializing.
130 145 $first_value = $meta_values[0];
131 146 if ( is_string( $first_value ) ) {
132 147 $meta_value = maybe_unserialize( $first_value );
133 - add_post_meta( $new_form_id, $meta_key, $meta_value );
148 + add_post_meta( $new_form_id, $meta_key, wp_slash( $meta_value ) );
134 149 }
135 150 }
136 151 } else {
137 152 // Handle serialized metas (get first value).
138 153 if ( is_array( $meta_values ) && isset( $meta_values[0] ) ) {
139 - add_post_meta( $new_form_id, $meta_key, $meta_values[0] );
154 + add_post_meta( $new_form_id, $meta_key, wp_slash( $meta_values[0] ) );
140 155 }
141 156 }
142 157 }
143 158 }