PluginProbe
User Submitted Posts – Enable Users to Submit Posts from the Front End / 20260916
User Submitted Posts – Enable Users to Submit Posts from the Front End v20260916
20260916 20260810 20260608 20230806 20230809 20230811 20230901 20230902 20230914 20231102 20240319 20240516 20240703 20241026 20250327 20250329 20251121 20251210 20260110 20260113 20260207 20260217 20260407 20260422 trunk All 59 releases
← All changes | user-submitted-posts.php +162 -56 2024102620260916 View file →
@@ -7,19 +7,17 @@
7 7 Author: Jeff Starr
8 8 Author URI: https://plugin-planet.com/
9 9 Donate link: https://monzillamedia.com/donate.html
10 10 Contributors: specialk
11 - Requires at least: 4.6
12 - Tested up to: 6.7
13 - Stable tag: 20241026
14 - Version: 20241026
11 + Requires at least: 4.7
12 + Tested up to: 7.1
13 + Stable tag: 20260916
14 + Version: 20260916
15 15 Requires PHP: 5.6.20
16 16 Text Domain: usp
17 17 Domain Path: /languages
18 18 License: GPL v2 or later
19 -*/
20 -
21 -/*
19 +
22 20 This program is free software; you can redistribute it and/or
23 21 modify it under the terms of the GNU General Public License
24 22 as published by the Free Software Foundation; either version
25 23 2 of the License, or (at your option) any later version.
@@ -31,16 +29,16 @@
31 29
32 30 You should have received a copy of the GNU General Public License
33 31 with this program. If not, visit: https://www.gnu.org/licenses/
34 32
35 - Copyright 2024 Monzilla Media. All rights reserved.
33 + Copyright 2011-2026 Monzilla Media. All rights reserved.
36 34 */
37 35
38 36 if (!defined('ABSPATH')) die();
39 37
40 -if (!defined('USP_WP_VERSION')) define('USP_WP_VERSION', '4.6');
41 -if (!defined('USP_VERSION')) define('USP_VERSION', '20241026');
42 -if (!defined('USP_PLUGIN')) define('USP_PLUGIN', esc_html__('User Submitted Posts', 'usp'));
38 +if (!defined('USP_WP_VERSION')) define('USP_WP_VERSION', '4.7');
39 +if (!defined('USP_VERSION')) define('USP_VERSION', '20260916');
40 +if (!defined('USP_PLUGIN')) define('USP_PLUGIN', 'User Submitted Posts');
43 41 if (!defined('USP_FILE')) define('USP_FILE', plugin_basename(__FILE__));
44 42 if (!defined('USP_PATH')) define('USP_PATH', plugin_dir_path(__FILE__));
45 43 if (!defined('USP_URL')) define('USP_URL', plugin_dir_url (__FILE__));
46 44
@@ -66,8 +64,10 @@
66 64 }
67 65
68 66 //
69 67
68 +
69 +
70 70 function usp_i18n_init() {
71 71
72 72 $domain = 'usp';
73 73
@@ -119,10 +119,10 @@
119 119 deactivate_plugins(USP_FILE);
120 120
121 121 $msg = '<strong>'. USP_PLUGIN .'</strong> ';
122 122 $msg .= esc_html__('requires WordPress ', 'usp') . USP_WP_VERSION;
123 - $msg .= esc_html__(' or higher, and has been deactivated! ', 'usp');
124 - $msg .= esc_html__('Please return to the', 'usp') .' <a href="'. admin_url() .'">';
123 + $msg .= esc_html__(' or higher, and has been deactivated. ', 'usp');
124 + $msg .= esc_html__('Please return to the', 'usp') .' <a href="'. admin_url('plugins.php') .'">';
125 125 $msg .= esc_html__('WordPress Admin Area', 'usp') .'</a> ';
126 126 $msg .= esc_html__('to upgrade WordPress and try again.', 'usp');
127 127
128 128 wp_die($msg);
@@ -293,8 +293,12 @@
293 293
294 294
295 295 function usp_get_submitted_category() {
296 296
297 + global $usp_options;
298 +
299 + $allowed_cats = isset($usp_options['categories']) ? array_map('intval', $usp_options['categories']) : array();
300 +
297 301 $category = isset($_POST['user-submitted-category']) ? $_POST['user-submitted-category'] : '';
298 302
299 303 if (is_array($category)) {
300 304
@@ -299,20 +303,30 @@
299 303 if (is_array($category)) {
300 304
301 305 $cats = array();
302 306
303 - foreach ($category as $cat) $cats[] = sanitize_text_field($cat);
307 + foreach ($category as $cat) $cats[] = intval($cat);
304 308
309 + $cats = array_intersect($cats, $allowed_cats);
310 +
305 311 } else {
306 312
307 313 if (strpos($category, ',') !== false) {
308 314
309 - $cats = array_map('trim', explode(',', $category));
315 + $cats = array_map('intval', array_map('trim', explode(',', $category)));
310 316
317 + $cats = array_intersect($cats, $allowed_cats);
318 +
311 319 } else {
312 320
313 - $cats = sanitize_text_field($category);
321 + $cats = intval($category);
314 322
323 + if (!in_array($cats, $allowed_cats)) {
324 +
325 + $cats = isset($allowed_cats[0]) ? $allowed_cats[0] : '';
326 +
327 + }
328 +
315 329 }
316 330
317 331 }
318 332
@@ -470,24 +484,13 @@
470 484 }
471 485
472 486 if ($post_id) {
473 487
474 - if (!empty($_POST['redirect-override'])) {
475 -
476 - $redirect = $_POST['redirect-override'];
477 -
478 - $redirect = remove_query_arg(array('usp-error'), $redirect);
479 - $redirect = add_query_arg(array('usp_redirect' => '1', 'success' => 1, 'post_id' => $post_id), $redirect);
480 -
481 - } else {
482 -
483 - $redirect = $_SERVER['REQUEST_URI'];
484 -
485 - $redirect = remove_query_arg(array('usp-error'), $redirect);
486 - $redirect = add_query_arg(array('success' => 1, 'post_id' => $post_id), $redirect);
487 -
488 - }
488 + $redirect = $_SERVER['REQUEST_URI'];
489 489
490 + $redirect = remove_query_arg(array('usp-error'), $redirect);
491 + $redirect = add_query_arg(array('success' => 1, 'post_id' => $post_id), $redirect);
492 +
490 493 do_action('usp_submit_success', $redirect);
491 494
492 495 } else {
493 496
@@ -525,8 +528,23 @@
525 528 }
526 529
527 530
528 531
532 +function usp_check_turnstile_keys() {
533 +
534 + global $usp_options;
535 +
536 + $site_key = isset($usp_options['turnstile_site_key']) ? $usp_options['turnstile_site_key'] : '';
537 + $secret_key = isset($usp_options['turnstile_secret_key']) ? $usp_options['turnstile_secret_key'] : '';
538 +
539 + if (empty($site_key) || empty($secret_key)) return false;
540 +
541 + return true;
542 +
543 +}
544 +
545 +
546 +
529 547 function usp_verify_recaptcha() {
530 548
531 549 global $usp_options;
532 550
@@ -557,8 +575,43 @@
557 575 }
558 576
559 577
560 578
579 +function usp_verify_turnstile() {
580 +
581 + global $usp_options;
582 +
583 + $site_key = isset($usp_options['turnstile_site_key']) ? $usp_options['turnstile_site_key'] : '';
584 + $secret_key = isset($usp_options['turnstile_secret_key']) ? $usp_options['turnstile_secret_key'] : '';
585 +
586 + if (!usp_check_turnstile_keys()) return false;
587 +
588 + $turnstile = isset($_POST['cf-turnstile-response']) ? $_POST['cf-turnstile-response'] : null;
589 +
590 + $headers = array(
591 + 'body' => array(
592 + 'secret' => $secret_key,
593 + 'response' => $turnstile,
594 + 'remoteip' => usp_get_ip_address()
595 + )
596 + );
597 +
598 + $verify = wp_remote_post('https://challenges.cloudflare.com/turnstile/v0/siteverify', $headers);
599 +
600 + $verify = wp_remote_retrieve_body($verify);
601 +
602 + $verify = json_decode($verify, true);
603 +
604 + $response = (isset($verify['success']) && $verify['success'] == 1) ? true : false;
605 +
606 + do_action('cfturnstile_after_check', $response, $verify);
607 +
608 + return $response;
609 +
610 +}
611 +
612 +
613 +
561 614 function usp_sanitize_content($content) {
562 615
563 616 $allowed_tags = wp_kses_allowed_html('post');
564 617
@@ -642,12 +695,12 @@
642 695 if (!empty($name) || !empty($email) || !empty($url) || !empty($ip)) {
643 696
644 697 echo '<ul style="margin-left:24px;list-style:square outside;">';
645 698
646 - if (!empty($name)) echo '<li>'. esc_html__('Submitter Name: ', 'usp') . $name .'</li>';
647 - if (!empty($email)) echo '<li>'. esc_html__('Submitter Email: ', 'usp') . $email .'</li>';
648 - if (!empty($url)) echo '<li>'. esc_html__('Submitter URL: ', 'usp') . $url .'</li>';
649 - if (!empty($ip) && !$usp_options['disable_ip_tracking']) echo '<li>'. esc_html__('Submitter IP: ', 'usp') . $ip .'</li>';
699 + if (!empty($name)) echo '<li>'. esc_html__('Submitter Name: ', 'usp') . esc_html($name) .'</li>';
700 + if (!empty($email)) echo '<li>'. esc_html__('Submitter Email: ', 'usp') . esc_html($email) .'</li>';
701 + if (!empty($url)) echo '<li>'. esc_html__('Submitter URL: ', 'usp') . esc_html($url) .'</li>';
702 + if (!empty($ip) && !$usp_options['disable_ip_tracking']) echo '<li>'. esc_html__('Submitter IP: ', 'usp') . esc_html($ip) .'</li>';
650 703
651 704 echo '</ul>';
652 705
653 706 }
@@ -674,9 +727,9 @@
674 727
675 728 return apply_filters('usp_form_shortcode', ob_get_clean());
676 729
677 730 }
678 -add_shortcode ('user-submitted-posts', 'usp_display_form');
731 +add_shortcode('user-submitted-posts', 'usp_display_form');
679 732
680 733
681 734
682 735 function user_submitted_posts() {
@@ -1314,8 +1367,14 @@
1314 1367 if (isset($usp_options['usp_recaptcha']) && ($usp_options['usp_recaptcha'] == 'show') && !usp_verify_recaptcha()) $newPost['error'][] = 'required-recaptcha';
1315 1368
1316 1369 }
1317 1370
1371 + if (usp_check_turnstile_keys()) {
1372 +
1373 + if (isset($usp_options['usp_turnstile']) && ($usp_options['usp_turnstile'] == 'show') && !usp_verify_turnstile()) $newPost['error'][] = 'required-recaptcha';
1374 +
1375 + }
1376 +
1318 1377 if (isset($usp_options['usp_captcha']) && ($usp_options['usp_captcha'] == 'show') && !usp_spamQuestion($captcha)) $newPost['error'][] = 'required-captcha';
1319 1378
1320 1379 if (isset($usp_options['usp_email']) && ($usp_options['usp_email'] == 'show')) {
1321 1380
@@ -1362,8 +1421,9 @@
1362 1421 $new_status = (isset($postData['post_status']) && !empty($postData['post_status'])) ? sanitize_text_field($postData['post_status']) : apply_filters('usp_post_status', 'pending');
1363 1422 $postData['post_status'] = apply_filters('usp_post_status', 'pending');
1364 1423
1365 1424 do_action('usp_insert_before', $postData);
1425 + $postData = apply_filters('usp_insert_post_vars', $postData);
1366 1426 $newPost['id'] = wp_insert_post($postData);
1367 1427 do_action('usp_insert_after', $newPost);
1368 1428
1369 1429 $post_id = isset($newPost['id']) ? $newPost['id'] : null;
@@ -1424,13 +1484,13 @@
1424 1484
1425 1485
1426 1486 function usp_include_deps() {
1427 1487
1428 - if (!function_exists('media_handle_upload')) {
1488 + if (!function_exists('media_handle_upload') || !function_exists('wp_crop_image')) {
1429 1489
1430 - require_once (ABSPATH .'/wp-admin/includes/media.php');
1431 - require_once (ABSPATH .'/wp-admin/includes/file.php');
1432 - require_once (ABSPATH .'/wp-admin/includes/image.php');
1490 + require_once(ABSPATH .'/wp-admin/includes/media.php');
1491 + require_once(ABSPATH .'/wp-admin/includes/file.php');
1492 + require_once(ABSPATH .'/wp-admin/includes/image.php');
1433 1493
1434 1494 }
1435 1495
1436 1496 }
@@ -1504,8 +1564,24 @@
1504 1564 return true;
1505 1565
1506 1566 }
1507 1567
1568 +function usp_post_cats($post_id) {
1569 +
1570 + $cats = '';
1571 +
1572 + foreach((get_the_category($post_id)) as $category) {
1573 +
1574 + $cats .= $category->cat_name .', ';
1575 +
1576 + }
1577 +
1578 + $cats = trim($cats, ', ');
1579 +
1580 + return $cats;
1581 +
1582 +}
1583 +
1508 1584 function usp_send_mail_alert($post_id, $title, $content, $author, $email, $url, $custom, $custom_2, $post_date) {
1509 1585
1510 1586 global $usp_options;
1511 1587
@@ -1513,8 +1589,9 @@
1513 1589
1514 1590 $blog_url = get_bloginfo('url'); // %%blog_url%%
1515 1591 $blog_name = get_bloginfo('name'); // %%blog_name%%
1516 1592 $post_url = get_permalink($post_id); // %%post_url%%
1593 + $post_cats = usp_post_cats($post_id); // %%post_cats%%
1517 1594 $admin_url = admin_url(); // %%admin_url%%
1518 1595 $post_title = $title; // %%post_title%%
1519 1596 $post_content = $content; // %%post_content%%
1520 1597 $post_author = $author; // %%post_author%%
@@ -1525,22 +1602,23 @@
1525 1602 $delete_link = usp_remote_delete_post_link($post_id); // %%delete_link%%
1526 1603
1527 1604 $patterns = array();
1528 1605
1529 - $patterns[0] = "/%%blog_url%%/";
1530 - $patterns[1] = "/%%blog_name%%/";
1531 - $patterns[2] = "/%%post_url%%/";
1532 - $patterns[3] = "/%%admin_url%%/";
1533 - $patterns[4] = "/%%post_title%%/";
1534 - $patterns[5] = "/%%post_content%%/";
1535 - $patterns[6] = "/%%post_author%%/";
1536 - $patterns[7] = "/%%user_email%%/";
1537 - $patterns[8] = "/%%user_url%%/";
1538 - $patterns[9] = "/%%edit_link%%/";
1539 - $patterns[10] = "/%%custom_field%%/";
1540 - $patterns[11] = "/%%custom_field_2%%/";
1541 - $patterns[12] = "/%%delete_link%%/";
1542 - $patterns[13] = "/%%post_date%%/";
1606 + $patterns[0] = "%%blog_url%%";
1607 + $patterns[1] = "%%blog_name%%";
1608 + $patterns[2] = "%%post_url%%";
1609 + $patterns[3] = "%%admin_url%%";
1610 + $patterns[4] = "%%post_title%%";
1611 + $patterns[5] = "%%post_content%%";
1612 + $patterns[6] = "%%post_author%%";
1613 + $patterns[7] = "%%user_email%%";
1614 + $patterns[8] = "%%user_url%%";
1615 + $patterns[9] = "%%edit_link%%";
1616 + $patterns[10] = "%%custom_field%%";
1617 + $patterns[11] = "%%custom_field_2%%";
1618 + $patterns[12] = "%%delete_link%%";
1619 + $patterns[13] = "%%post_date%%";
1620 + $patterns[14] = "%%post_cats%%";
1543 1621
1544 1622 $replacements = array();
1545 1623
1546 1624 $replacements[0] = $blog_url;
@@ -1556,19 +1634,28 @@
1556 1634 $replacements[10] = $custom;
1557 1635 $replacements[11] = $custom_2;
1558 1636 $replacements[12] = $delete_link;
1559 1637 $replacements[13] = $post_date;
1638 + $replacements[14] = $post_cats;
1560 1639
1561 1640 //
1562 1641
1563 1642 $subject_default = $blog_name .': New user-submitted post!';
1564 1643 $subject = (isset($usp_options['email_alert_subject']) && !empty($usp_options['email_alert_subject'])) ? $usp_options['email_alert_subject'] : $subject_default;
1565 - $subject = preg_replace($patterns, $replacements, $subject);
1644 + for($i = 0; $i < count($patterns); $i++) {
1645 + $pattern = isset($patterns[$i]) ? $patterns[$i] : '';
1646 + $replace = isset($replacements[$i]) ? $replacements[$i] : '';
1647 + $subject = str_replace($pattern, $replace, $subject);
1648 + }
1566 1649 $subject = apply_filters('usp_mail_subject', $subject);
1567 1650
1568 1651 $message_default = 'Hello, there is a new user-submitted post:'. "\r\n\n" . 'Title: '. $post_title . "\r\n\n" .'Visit Admin Area: '. $admin_url;
1569 1652 $message = (isset($usp_options['email_alert_message']) && !empty($usp_options['email_alert_message'])) ? $usp_options['email_alert_message'] : $message_default;
1570 - $message = preg_replace($patterns, $replacements, $message);
1653 + for($i = 0; $i < count($patterns); $i++) {
1654 + $pattern = isset($patterns[$i]) ? $patterns[$i] : '';
1655 + $replace = isset($replacements[$i]) ? $replacements[$i] : '';
1656 + $message = str_replace($pattern, $replace, $message);
1657 + }
1571 1658 $message = apply_filters('usp_mail_message', $message);
1572 1659
1573 1660 $html = isset($usp_options['usp_email_html']) ? $usp_options['usp_email_html'] : false;
1574 1661 $format = $html ? 'text/html' : 'text/plain';
@@ -1858,4 +1945,23 @@
1858 1945 }
1859 1946
1860 1947 }
1861 1948 add_action('wp_logout', 'usp_clear_cookies');
1949 +
1950 +
1951 +
1952 +function usp_add_new_options() {
1953 +
1954 + global $usp_options;
1955 +
1956 + $turnstile = isset($usp_options['usp_turnstile']) ? true : false;
1957 +
1958 + if (empty($turnstile)) {
1959 +
1960 + $usp_options['usp_turnstile'] = 'hide';
1961 +
1962 + $update_option = update_option('usp_options', $usp_options);
1963 +
1964 + }
1965 +
1966 +}
1967 +add_action('admin_init', 'usp_add_new_options');