PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.12.8
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.12.8
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
← All changes | inc/email/email-template.php +7 -3 2.7.1 → 2.12.8 View file →
@@ -231,9 +231,9 @@
231 231 }
232 232
233 233 $label = explode( '-lbl-', $field_name )[1];
234 234 $label = explode( '-', $label )[0];
235 - $field_label = $label ? Helper::decrypt( $label ) : '';
235 + $field_label = $label ? Helper::decode( $label ) : '';
236 236
237 237 $field_block_name = Helper::get_block_name_from_field( $field_name );
238 238
239 239 /**
@@ -249,9 +249,12 @@
249 249 * @param array $field_data Field data containing:
250 250 * 'value' => mixed The field value
251 251 * 'label' => string The field name/key
252 252 * 'block_name' => string The block type identifier
253 - * 'processed_label' => string The decrypted human readable label
253 + * 'processed_label' => string The human readable label, base64-decoded
254 + * out of the submitted field key. Submitter-
255 + * controlled and unauthenticated — escape it
256 + * for the output context (esc_html() for HTML).
254 257 */
255 258 do_action(
256 259 'srfm_before_processing_all_data_field',
257 260 [
@@ -315,9 +318,10 @@
315 318
316 319 ?>
317 320 <tr class="field-label">
318 321 <th style="<?php echo esc_attr( $td_style ); ?>color: #1E293B;background-color: #F1F5F9;">
319 - <strong><?php echo wp_kses_post( html_entity_decode( $field_label ) ); ?>:</strong>
322 + <?php // The label is decoded from the submitted field key, so it is attacker-controllable — escape it as text, never as markup. ?>
323 + <strong><?php echo esc_html( html_entity_decode( $field_label ) ); ?>:</strong>
320 324 </th>
321 325 </tr>
322 326 <tr class="field-value">
323 327 <td style="<?php echo esc_attr( $td_style ); ?>color: #475569;">