PluginProbe
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets / 4.5.6
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets v4.5.6
4.5.6 4.5.5 4.5.4 4.2.1 4.2.2 4.2.3 4.5.0 4.5.2 4.5.3 4.2.0 4.1.18 4.1.17 4.1.16 4.1.15 4.1.14 4.1.13 4.1.12 4.1.11 4.1.10 4.1.9 4.1.8 4.0.9 4.1.0 4.1.1 4.1.2 All 148 releases
← All changes | modules/newsletter/module.php +34 -4 4.1.10 → 4.5.6 View file →
@@ -44,8 +44,15 @@
44 44
45 45 $list_id = (!empty($options['mailchimp_list_id'])) ? $options['mailchimp_list_id'] : ''; // Your list is here
46 46 $api_key = (!empty($options['mailchimp_api_key'])) ? $options['mailchimp_api_key'] : ''; // Your mailchimp api key here
47 47
48 + // This endpoint is registered on wp_ajax_nopriv_, so it is reachable before the
49 + // site owner has configured Mailchimp at all. Without credentials the request
50 + // below would be built against an unresolvable host and fail.
51 + if (empty($api_key) || empty($list_id) || false === strpos($api_key, '-')) {
52 + return null;
53 + }
54 +
48 55 $args = array(
49 56 'method' => 'PUT',
50 57 'headers' => array(
51 58 'Authorization' => 'Basic ' . base64_encode('user:' . $api_key)
@@ -57,10 +64,16 @@
57 64 ))
58 65 );
59 66 $response = wp_remote_post('https://' . substr($api_key, strpos($api_key, '-') + 1) . '.api.mailchimp.com/3.0/lists/' . $list_id . '/members/' . md5(strtolower($email)), $args);
60 67
61 - $body = json_decode($response['body']);
68 + // A transport failure returns WP_Error, which is an object: indexing it as an
69 + // array is a fatal. The caller already handles a null/!is_object result.
70 + if (is_wp_error($response)) {
71 + return null;
72 + }
62 73
74 + $body = json_decode(wp_remote_retrieve_body($response));
75 +
63 76 return $body;
64 77 }
65 78
66 79
@@ -66,12 +79,29 @@
66 79
67 80 public function mailchimp_subscribe()
68 81 {
69 82
70 - $fname = (isset($_POST['fname']) && !empty($_POST['fname'])) ? sanitize_text_field($_POST['fname']) : '';
83 + // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended -- unauthenticated public newsletter subscribe form; input is sanitized and the e-mail validated before use, no nonce is expected from anonymous visitors.
84 + $fname = (isset($_POST['fname']) && !empty($_POST['fname'])) ? sanitize_text_field(wp_unslash($_POST['fname'])) : '';
71 85
72 - $result = $this->mailchimp_subscriber_status(sanitize_text_field($_POST['email']), 'subscribed', ['FNAME' => $fname, 'LNAME' => '']);
73 -
86 + // Validate the address before hitting the Mailchimp API. This endpoint is
87 + // unauthenticated, so reject anything that is not a real e-mail rather
88 + // than forwarding arbitrary input to the list.
89 + // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended -- unauthenticated public newsletter subscribe form; input is sanitized and the e-mail validated before use, no nonce is expected from anonymous visitors.
90 + $email = isset($_POST['email']) ? sanitize_email(wp_unslash($_POST['email'])) : '';
91 +
92 + if (empty($email) || ! is_email($email)) {
93 + echo '<div class="upk-text-warning">' . esc_html_x('Please enter a valid email address.', 'Mailchimp String', 'ultimate-post-kit') . '</div>';
94 + die;
95 + }
96 +
97 + $result = $this->mailchimp_subscriber_status($email, 'subscribed', ['FNAME' => $fname, 'LNAME' => '']);
98 +
99 + if (! is_object($result) || ! isset($result->status)) {
100 + echo '<div class="upk-text-danger">' . esc_html_x('An unexpected internal error has occurred. Please contact Support for more information.', 'Mailchimp String', 'ultimate-post-kit') . '</div>';
101 + die;
102 + }
103 +
74 104 if ($result->status == 400) {
75 105 if (isset($result->detail) && !empty($result->detail)) {
76 106 echo '<div class="upk-text-warning">' . esc_html($result->detail) . '</div>';
77 107 } else {