'', 'LNAME' => '')) { $options = get_option('ultimate_post_kit_api_settings'); $list_id = (!empty($options['mailchimp_list_id'])) ? $options['mailchimp_list_id'] : ''; // Your list is here $api_key = (!empty($options['mailchimp_api_key'])) ? $options['mailchimp_api_key'] : ''; // Your mailchimp api key here // This endpoint is registered on wp_ajax_nopriv_, so it is reachable before the // site owner has configured Mailchimp at all. Without credentials the request // below would be built against an unresolvable host and fail. if (empty($api_key) || empty($list_id) || false === strpos($api_key, '-')) { return null; } $args = array( 'method' => 'PUT', 'headers' => array( 'Authorization' => 'Basic ' . base64_encode('user:' . $api_key) ), 'body' => json_encode(array( 'email_address' => $email, 'status' => $status, 'merge_fields' => $merge_fields )) ); $response = wp_remote_post('https://' . substr($api_key, strpos($api_key, '-') + 1) . '.api.mailchimp.com/3.0/lists/' . $list_id . '/members/' . md5(strtolower($email)), $args); // A transport failure returns WP_Error, which is an object: indexing it as an // array is a fatal. The caller already handles a null/!is_object result. if (is_wp_error($response)) { return null; } $body = json_decode(wp_remote_retrieve_body($response)); return $body; } public function mailchimp_subscribe() { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended -- unauthenticated public newsletter subscribe form; input is sanitized and the e-mail validated before use, no nonce is expected from anonymous visitors. $fname = (isset($_POST['fname']) && !empty($_POST['fname'])) ? sanitize_text_field(wp_unslash($_POST['fname'])) : ''; // Validate the address before hitting the Mailchimp API. This endpoint is // unauthenticated, so reject anything that is not a real e-mail rather // than forwarding arbitrary input to the list. // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended -- unauthenticated public newsletter subscribe form; input is sanitized and the e-mail validated before use, no nonce is expected from anonymous visitors. $email = isset($_POST['email']) ? sanitize_email(wp_unslash($_POST['email'])) : ''; if (empty($email) || ! is_email($email)) { echo '