PluginProbe
User Submitted Posts – Enable Users to Submit Posts from the Front End / 20260916
User Submitted Posts – Enable Users to Submit Posts from the Front End v20260916
20260916 20260810 20260608 20230806 20230809 20230811 20230901 20230902 20230914 20231102 20240319 20240516 20240703 20241026 20250327 20250329 20251121 20251210 20260110 20260113 20260207 20260217 20260407 20260422 trunk All 59 releases
← All changes | user-submitted-posts.php +191 -62 2023110220260916 View file →
@@ -2,24 +2,22 @@
2 2 /*
3 3 Plugin Name: User Submitted Posts
4 4 Plugin URI: https://perishablepress.com/user-submitted-posts/
5 5 Description: Enables your visitors to submit posts and images from anywhere on your site.
6 - Tags: frontend post, submit post, guest post, visitor post, content restriction, public post, share post, user post, user submitted post, upload
6 + Tags: frontend post, submit post, guest post, visitor post, public post
7 7 Author: Jeff Starr
8 8 Author URI: https://plugin-planet.com/
9 9 Donate link: https://monzillamedia.com/donate.html
10 10 Contributors: specialk
11 - Requires at least: 4.6
12 - Tested up to: 6.4
13 - Stable tag: 20231102
14 - Version: 20231102
11 + Requires at least: 4.7
12 + Tested up to: 7.1
13 + Stable tag: 20260916
14 + Version: 20260916
15 15 Requires PHP: 5.6.20
16 16 Text Domain: usp
17 17 Domain Path: /languages
18 18 License: GPL v2 or later
19 -*/
20 -
21 -/*
19 +
22 20 This program is free software; you can redistribute it and/or
23 21 modify it under the terms of the GNU General Public License
24 22 as published by the Free Software Foundation; either version
25 23 2 of the License, or (at your option) any later version.
@@ -31,16 +29,16 @@
31 29
32 30 You should have received a copy of the GNU General Public License
33 31 with this program. If not, visit: https://www.gnu.org/licenses/
34 32
35 - Copyright 2023 Monzilla Media. All rights reserved.
33 + Copyright 2011-2026 Monzilla Media. All rights reserved.
36 34 */
37 35
38 36 if (!defined('ABSPATH')) die();
39 37
40 -if (!defined('USP_WP_VERSION')) define('USP_WP_VERSION', '4.6');
41 -if (!defined('USP_VERSION')) define('USP_VERSION', '20231102');
42 -if (!defined('USP_PLUGIN')) define('USP_PLUGIN', esc_html__('User Submitted Posts', 'usp'));
38 +if (!defined('USP_WP_VERSION')) define('USP_WP_VERSION', '4.7');
39 +if (!defined('USP_VERSION')) define('USP_VERSION', '20260916');
40 +if (!defined('USP_PLUGIN')) define('USP_PLUGIN', 'User Submitted Posts');
43 41 if (!defined('USP_FILE')) define('USP_FILE', plugin_basename(__FILE__));
44 42 if (!defined('USP_PATH')) define('USP_PATH', plugin_dir_path(__FILE__));
45 43 if (!defined('USP_URL')) define('USP_URL', plugin_dir_url (__FILE__));
46 44
@@ -66,8 +64,10 @@
66 64 }
67 65
68 66 //
69 67
68 +
69 +
70 70 function usp_i18n_init() {
71 71
72 72 $domain = 'usp';
73 73
@@ -119,10 +119,10 @@
119 119 deactivate_plugins(USP_FILE);
120 120
121 121 $msg = '<strong>'. USP_PLUGIN .'</strong> ';
122 122 $msg .= esc_html__('requires WordPress ', 'usp') . USP_WP_VERSION;
123 - $msg .= esc_html__(' or higher, and has been deactivated! ', 'usp');
124 - $msg .= esc_html__('Please return to the', 'usp') .' <a href="'. admin_url() .'">';
123 + $msg .= esc_html__(' or higher, and has been deactivated. ', 'usp');
124 + $msg .= esc_html__('Please return to the', 'usp') .' <a href="'. admin_url('plugins.php') .'">';
125 125 $msg .= esc_html__('WordPress Admin Area', 'usp') .'</a> ';
126 126 $msg .= esc_html__('to upgrade WordPress and try again.', 'usp');
127 127
128 128 wp_die($msg);
@@ -293,8 +293,12 @@
293 293
294 294
295 295 function usp_get_submitted_category() {
296 296
297 + global $usp_options;
298 +
299 + $allowed_cats = isset($usp_options['categories']) ? array_map('intval', $usp_options['categories']) : array();
300 +
297 301 $category = isset($_POST['user-submitted-category']) ? $_POST['user-submitted-category'] : '';
298 302
299 303 if (is_array($category)) {
300 304
@@ -299,20 +303,30 @@
299 303 if (is_array($category)) {
300 304
301 305 $cats = array();
302 306
303 - foreach ($category as $cat) $cats[] = sanitize_text_field($cat);
307 + foreach ($category as $cat) $cats[] = intval($cat);
304 308
309 + $cats = array_intersect($cats, $allowed_cats);
310 +
305 311 } else {
306 312
307 313 if (strpos($category, ',') !== false) {
308 314
309 - $cats = array_map('trim', explode(',', $category));
315 + $cats = array_map('intval', array_map('trim', explode(',', $category)));
310 316
317 + $cats = array_intersect($cats, $allowed_cats);
318 +
311 319 } else {
312 320
313 - $cats = sanitize_text_field($category);
321 + $cats = intval($category);
314 322
323 + if (!in_array($cats, $allowed_cats)) {
324 +
325 + $cats = isset($allowed_cats[0]) ? $allowed_cats[0] : '';
326 +
327 + }
328 +
315 329 }
316 330
317 331 }
318 332
@@ -470,24 +484,13 @@
470 484 }
471 485
472 486 if ($post_id) {
473 487
474 - if (!empty($_POST['redirect-override'])) {
475 -
476 - $redirect = $_POST['redirect-override'];
477 -
478 - $redirect = remove_query_arg(array('usp-error'), $redirect);
479 - $redirect = add_query_arg(array('usp_redirect' => '1', 'success' => 1, 'post_id' => $post_id), $redirect);
480 -
481 - } else {
482 -
483 - $redirect = $_SERVER['REQUEST_URI'];
484 -
485 - $redirect = remove_query_arg(array('usp-error'), $redirect);
486 - $redirect = add_query_arg(array('success' => 1, 'post_id' => $post_id), $redirect);
487 -
488 - }
488 + $redirect = $_SERVER['REQUEST_URI'];
489 489
490 + $redirect = remove_query_arg(array('usp-error'), $redirect);
491 + $redirect = add_query_arg(array('success' => 1, 'post_id' => $post_id), $redirect);
492 +
490 493 do_action('usp_submit_success', $redirect);
491 494
492 495 } else {
493 496
@@ -525,8 +528,23 @@
525 528 }
526 529
527 530
528 531
532 +function usp_check_turnstile_keys() {
533 +
534 + global $usp_options;
535 +
536 + $site_key = isset($usp_options['turnstile_site_key']) ? $usp_options['turnstile_site_key'] : '';
537 + $secret_key = isset($usp_options['turnstile_secret_key']) ? $usp_options['turnstile_secret_key'] : '';
538 +
539 + if (empty($site_key) || empty($secret_key)) return false;
540 +
541 + return true;
542 +
543 +}
544 +
545 +
546 +
529 547 function usp_verify_recaptcha() {
530 548
531 549 global $usp_options;
532 550
@@ -557,8 +575,43 @@
557 575 }
558 576
559 577
560 578
579 +function usp_verify_turnstile() {
580 +
581 + global $usp_options;
582 +
583 + $site_key = isset($usp_options['turnstile_site_key']) ? $usp_options['turnstile_site_key'] : '';
584 + $secret_key = isset($usp_options['turnstile_secret_key']) ? $usp_options['turnstile_secret_key'] : '';
585 +
586 + if (!usp_check_turnstile_keys()) return false;
587 +
588 + $turnstile = isset($_POST['cf-turnstile-response']) ? $_POST['cf-turnstile-response'] : null;
589 +
590 + $headers = array(
591 + 'body' => array(
592 + 'secret' => $secret_key,
593 + 'response' => $turnstile,
594 + 'remoteip' => usp_get_ip_address()
595 + )
596 + );
597 +
598 + $verify = wp_remote_post('https://challenges.cloudflare.com/turnstile/v0/siteverify', $headers);
599 +
600 + $verify = wp_remote_retrieve_body($verify);
601 +
602 + $verify = json_decode($verify, true);
603 +
604 + $response = (isset($verify['success']) && $verify['success'] == 1) ? true : false;
605 +
606 + do_action('cfturnstile_after_check', $response, $verify);
607 +
608 + return $response;
609 +
610 +}
611 +
612 +
613 +
561 614 function usp_sanitize_content($content) {
562 615
563 616 $allowed_tags = wp_kses_allowed_html('post');
564 617
@@ -642,12 +695,12 @@
642 695 if (!empty($name) || !empty($email) || !empty($url) || !empty($ip)) {
643 696
644 697 echo '<ul style="margin-left:24px;list-style:square outside;">';
645 698
646 - if (!empty($name)) echo '<li>'. esc_html__('Submitter Name: ', 'usp') . $name .'</li>';
647 - if (!empty($email)) echo '<li>'. esc_html__('Submitter Email: ', 'usp') . $email .'</li>';
648 - if (!empty($url)) echo '<li>'. esc_html__('Submitter URL: ', 'usp') . $url .'</li>';
649 - if (!empty($ip) && !$usp_options['disable_ip_tracking']) echo '<li>'. esc_html__('Submitter IP: ', 'usp') . $ip .'</li>';
699 + if (!empty($name)) echo '<li>'. esc_html__('Submitter Name: ', 'usp') . esc_html($name) .'</li>';
700 + if (!empty($email)) echo '<li>'. esc_html__('Submitter Email: ', 'usp') . esc_html($email) .'</li>';
701 + if (!empty($url)) echo '<li>'. esc_html__('Submitter URL: ', 'usp') . esc_html($url) .'</li>';
702 + if (!empty($ip) && !$usp_options['disable_ip_tracking']) echo '<li>'. esc_html__('Submitter IP: ', 'usp') . esc_html($ip) .'</li>';
650 703
651 704 echo '</ul>';
652 705
653 706 }
@@ -674,9 +727,9 @@
674 727
675 728 return apply_filters('usp_form_shortcode', ob_get_clean());
676 729
677 730 }
678 -add_shortcode ('user-submitted-posts', 'usp_display_form');
731 +add_shortcode('user-submitted-posts', 'usp_display_form');
679 732
680 733
681 734
682 735 function user_submitted_posts() {
@@ -1006,12 +1059,26 @@
1006 1059 global $usp_options;
1007 1060
1008 1061 if ($usp_options['titles_unique']) {
1009 1062
1010 - $check_post = get_page_by_title($title, OBJECT, 'post');
1063 + $args = array(
1064 +
1065 + 'post_type' => 'post',
1066 + 'title' => $title,
1067 + 'post_status' => 'all',
1068 + 'posts_per_page' => 1,
1069 + 'no_found_rows' => true,
1070 + 'ignore_sticky_posts' => true,
1071 + 'update_post_term_cache' => false,
1072 + 'update_post_meta_cache' => false,
1073 + 'orderby' => 'post_date ID',
1074 + 'order' => 'ASC'
1075 + );
1011 1076
1012 - if ($check_post && $check_post->ID) return false;
1077 + $check_post = new WP_Query(apply_filters('usp_check_duplicates', $args));
1013 1078
1079 + if (!empty($check_post->post)) return false;
1080 +
1014 1081 }
1015 1082
1016 1083 return true;
1017 1084
@@ -1168,9 +1235,9 @@
1168 1235 }
1169 1236
1170 1237 $file = file_exists($file) ? usp_unique_filename($file) : $file;
1171 1238
1172 - if (in_array($ext, array('jpg', 'jpeg', 'jpe', 'gif', 'png', 'bmp', 'tif', 'tiff', 'ico', 'webp', 'heic', 'heif', 'svg'))) $bytes = file_put_contents($file, $file_local);
1239 + if (in_array(strtolower($ext), array('jpg', 'jpeg', 'jpe', 'gif', 'png', 'bmp', 'tif', 'tiff', 'ico', 'webp', 'heic', 'heif', 'svg'))) $bytes = file_put_contents($file, $file_local);
1173 1240
1174 1241 $file_type = isset($wp_filetype['type']) ? $wp_filetype['type'] : null;
1175 1242
1176 1243 $params = apply_filters('wp_handle_upload', array('file' => $file, 'url' => $guid, 'type' => $file_type));
@@ -1300,8 +1367,14 @@
1300 1367 if (isset($usp_options['usp_recaptcha']) && ($usp_options['usp_recaptcha'] == 'show') && !usp_verify_recaptcha()) $newPost['error'][] = 'required-recaptcha';
1301 1368
1302 1369 }
1303 1370
1371 + if (usp_check_turnstile_keys()) {
1372 +
1373 + if (isset($usp_options['usp_turnstile']) && ($usp_options['usp_turnstile'] == 'show') && !usp_verify_turnstile()) $newPost['error'][] = 'required-recaptcha';
1374 +
1375 + }
1376 +
1304 1377 if (isset($usp_options['usp_captcha']) && ($usp_options['usp_captcha'] == 'show') && !usp_spamQuestion($captcha)) $newPost['error'][] = 'required-captcha';
1305 1378
1306 1379 if (isset($usp_options['usp_email']) && ($usp_options['usp_email'] == 'show')) {
1307 1380
@@ -1321,10 +1394,13 @@
1321 1394
1322 1395 if (isset($usp_options['titles_unique']) && $usp_options['titles_unique'] && !usp_check_duplicates($title)) $newPost['error'][] = 'duplicate-title';
1323 1396 if (!empty($verify)) $newPost['error'][] = 'spam-verify';
1324 1397
1325 - if (isset($usp_options['custom_checkbox']) && !empty($usp_options['custom_checkbox']) && empty($checkbox)) $newPost['error'][] = 'required-checkbox';
1398 + $checkbox_display = (isset($usp_options['custom_checkbox']) && !empty($usp_options['custom_checkbox'])) ? true : false;
1399 + $checkbox_required = (isset($usp_options['custom_checkbox_req']) && !empty($usp_options['custom_checkbox_req'])) ? true : false;
1326 1400
1401 + if ($checkbox_display && $checkbox_required && empty($checkbox)) $newPost['error'][] = 'required-checkbox';
1402 +
1327 1403 if (isset($newPost['error']) && !empty($newPost['error'])) {
1328 1404
1329 1405 foreach ($newPost['error'] as $e) {
1330 1406
@@ -1345,8 +1421,9 @@
1345 1421 $new_status = (isset($postData['post_status']) && !empty($postData['post_status'])) ? sanitize_text_field($postData['post_status']) : apply_filters('usp_post_status', 'pending');
1346 1422 $postData['post_status'] = apply_filters('usp_post_status', 'pending');
1347 1423
1348 1424 do_action('usp_insert_before', $postData);
1425 + $postData = apply_filters('usp_insert_post_vars', $postData);
1349 1426 $newPost['id'] = wp_insert_post($postData);
1350 1427 do_action('usp_insert_after', $newPost);
1351 1428
1352 1429 $post_id = isset($newPost['id']) ? $newPost['id'] : null;
@@ -1385,10 +1462,14 @@
1385 1462 if (!empty($url)) update_post_meta($post_id, 'user_submit_url', $url);
1386 1463
1387 1464 if (!empty($ip) && !$usp_options['disable_ip_tracking']) update_post_meta($post_id, 'user_submit_ip', $ip);
1388 1465
1389 - usp_send_mail_alert($post_id, $title, $content, $author, $email, $url, $custom, $custom_2);
1466 + $post_date = apply_filters('usp_post_meta_submit_time_format', get_the_time('l, F j, Y @ h:i:s a', $post_id));
1390 1467
1468 + update_post_meta($post_id, 'usp-post-time', $post_date);
1469 +
1470 + usp_send_mail_alert($post_id, $title, $content, $author, $email, $url, $custom, $custom_2, $post_date);
1471 +
1391 1472 }
1392 1473
1393 1474 } else {
1394 1475
@@ -1403,13 +1484,13 @@
1403 1484
1404 1485
1405 1486 function usp_include_deps() {
1406 1487
1407 - if (!function_exists('media_handle_upload')) {
1488 + if (!function_exists('media_handle_upload') || !function_exists('wp_crop_image')) {
1408 1489
1409 - require_once (ABSPATH .'/wp-admin/includes/media.php');
1410 - require_once (ABSPATH .'/wp-admin/includes/file.php');
1411 - require_once (ABSPATH .'/wp-admin/includes/image.php');
1490 + require_once(ABSPATH .'/wp-admin/includes/media.php');
1491 + require_once(ABSPATH .'/wp-admin/includes/file.php');
1492 + require_once(ABSPATH .'/wp-admin/includes/image.php');
1412 1493
1413 1494 }
1414 1495
1415 1496 }
@@ -1483,10 +1564,26 @@
1483 1564 return true;
1484 1565
1485 1566 }
1486 1567
1487 -function usp_send_mail_alert($post_id, $title, $content, $author, $email, $url, $custom, $custom_2) {
1568 +function usp_post_cats($post_id) {
1488 1569
1570 + $cats = '';
1571 +
1572 + foreach((get_the_category($post_id)) as $category) {
1573 +
1574 + $cats .= $category->cat_name .', ';
1575 +
1576 + }
1577 +
1578 + $cats = trim($cats, ', ');
1579 +
1580 + return $cats;
1581 +
1582 +}
1583 +
1584 +function usp_send_mail_alert($post_id, $title, $content, $author, $email, $url, $custom, $custom_2, $post_date) {
1585 +
1489 1586 global $usp_options;
1490 1587
1491 1588 if (isset($usp_options['usp_email_alerts']) && $usp_options['usp_email_alerts']) {
1492 1589
@@ -1492,8 +1589,9 @@
1492 1589
1493 1590 $blog_url = get_bloginfo('url'); // %%blog_url%%
1494 1591 $blog_name = get_bloginfo('name'); // %%blog_name%%
1495 1592 $post_url = get_permalink($post_id); // %%post_url%%
1593 + $post_cats = usp_post_cats($post_id); // %%post_cats%%
1496 1594 $admin_url = admin_url(); // %%admin_url%%
1497 1595 $post_title = $title; // %%post_title%%
1498 1596 $post_content = $content; // %%post_content%%
1499 1597 $post_author = $author; // %%post_author%%
@@ -1504,21 +1602,23 @@
1504 1602 $delete_link = usp_remote_delete_post_link($post_id); // %%delete_link%%
1505 1603
1506 1604 $patterns = array();
1507 1605
1508 - $patterns[0] = "/%%blog_url%%/";
1509 - $patterns[1] = "/%%blog_name%%/";
1510 - $patterns[2] = "/%%post_url%%/";
1511 - $patterns[3] = "/%%admin_url%%/";
1512 - $patterns[4] = "/%%post_title%%/";
1513 - $patterns[5] = "/%%post_content%%/";
1514 - $patterns[6] = "/%%post_author%%/";
1515 - $patterns[7] = "/%%user_email%%/";
1516 - $patterns[8] = "/%%user_url%%/";
1517 - $patterns[9] = "/%%edit_link%%/";
1518 - $patterns[10] = "/%%custom_field%%/";
1519 - $patterns[11] = "/%%custom_field_2%%/";
1520 - $patterns[12] = "/%%delete_link%%/";
1606 + $patterns[0] = "%%blog_url%%";
1607 + $patterns[1] = "%%blog_name%%";
1608 + $patterns[2] = "%%post_url%%";
1609 + $patterns[3] = "%%admin_url%%";
1610 + $patterns[4] = "%%post_title%%";
1611 + $patterns[5] = "%%post_content%%";
1612 + $patterns[6] = "%%post_author%%";
1613 + $patterns[7] = "%%user_email%%";
1614 + $patterns[8] = "%%user_url%%";
1615 + $patterns[9] = "%%edit_link%%";
1616 + $patterns[10] = "%%custom_field%%";
1617 + $patterns[11] = "%%custom_field_2%%";
1618 + $patterns[12] = "%%delete_link%%";
1619 + $patterns[13] = "%%post_date%%";
1620 + $patterns[14] = "%%post_cats%%";
1521 1621
1522 1622 $replacements = array();
1523 1623
1524 1624 $replacements[0] = $blog_url;
@@ -1533,19 +1633,29 @@
1533 1633 $replacements[9] = $edit_link;
1534 1634 $replacements[10] = $custom;
1535 1635 $replacements[11] = $custom_2;
1536 1636 $replacements[12] = $delete_link;
1637 + $replacements[13] = $post_date;
1638 + $replacements[14] = $post_cats;
1537 1639
1538 1640 //
1539 1641
1540 1642 $subject_default = $blog_name .': New user-submitted post!';
1541 1643 $subject = (isset($usp_options['email_alert_subject']) && !empty($usp_options['email_alert_subject'])) ? $usp_options['email_alert_subject'] : $subject_default;
1542 - $subject = preg_replace($patterns, $replacements, $subject);
1644 + for($i = 0; $i < count($patterns); $i++) {
1645 + $pattern = isset($patterns[$i]) ? $patterns[$i] : '';
1646 + $replace = isset($replacements[$i]) ? $replacements[$i] : '';
1647 + $subject = str_replace($pattern, $replace, $subject);
1648 + }
1543 1649 $subject = apply_filters('usp_mail_subject', $subject);
1544 1650
1545 1651 $message_default = 'Hello, there is a new user-submitted post:'. "\r\n\n" . 'Title: '. $post_title . "\r\n\n" .'Visit Admin Area: '. $admin_url;
1546 1652 $message = (isset($usp_options['email_alert_message']) && !empty($usp_options['email_alert_message'])) ? $usp_options['email_alert_message'] : $message_default;
1547 - $message = preg_replace($patterns, $replacements, $message);
1653 + for($i = 0; $i < count($patterns); $i++) {
1654 + $pattern = isset($patterns[$i]) ? $patterns[$i] : '';
1655 + $replace = isset($replacements[$i]) ? $replacements[$i] : '';
1656 + $message = str_replace($pattern, $replace, $message);
1657 + }
1548 1658 $message = apply_filters('usp_mail_message', $message);
1549 1659
1550 1660 $html = isset($usp_options['usp_email_html']) ? $usp_options['usp_email_html'] : false;
1551 1661 $format = $html ? 'text/html' : 'text/plain';
@@ -1835,4 +1945,23 @@
1835 1945 }
1836 1946
1837 1947 }
1838 1948 add_action('wp_logout', 'usp_clear_cookies');
1949 +
1950 +
1951 +
1952 +function usp_add_new_options() {
1953 +
1954 + global $usp_options;
1955 +
1956 + $turnstile = isset($usp_options['usp_turnstile']) ? true : false;
1957 +
1958 + if (empty($turnstile)) {
1959 +
1960 + $usp_options['usp_turnstile'] = 'hide';
1961 +
1962 + $update_option = update_option('usp_options', $usp_options);
1963 +
1964 + }
1965 +
1966 +}
1967 +add_action('admin_init', 'usp_add_new_options');