PluginProbe
User Submitted Posts – Enable Users to Submit Posts from the Front End / 20260916
User Submitted Posts – Enable Users to Submit Posts from the Front End v20260916
20260916 20260810 20260608 20230806 20230809 20230811 20230901 20230902 20230914 20231102 20240319 20240516 20240703 20241026 20250327 20250329 20251121 20251210 20260110 20260113 20260207 20260217 20260407 20260422 trunk All 59 releases
← All changes | user-submitted-posts.php +76 -48 2025112120260916 View file →
@@ -8,18 +8,16 @@
8 8 Author URI: https://plugin-planet.com/
9 9 Donate link: https://monzillamedia.com/donate.html
10 10 Contributors: specialk
11 11 Requires at least: 4.7
12 - Tested up to: 6.9
13 - Stable tag: 20251121
14 - Version: 20251121
12 + Tested up to: 7.1
13 + Stable tag: 20260916
14 + Version: 20260916
15 15 Requires PHP: 5.6.20
16 16 Text Domain: usp
17 17 Domain Path: /languages
18 18 License: GPL v2 or later
19 -*/
20 -
21 -/*
19 +
22 20 This program is free software; you can redistribute it and/or
23 21 modify it under the terms of the GNU General Public License
24 22 as published by the Free Software Foundation; either version
25 23 2 of the License, or (at your option) any later version.
@@ -31,15 +29,15 @@
31 29
32 30 You should have received a copy of the GNU General Public License
33 31 with this program. If not, visit: https://www.gnu.org/licenses/
34 32
35 - Copyright 2025 Monzilla Media. All rights reserved.
33 + Copyright 2011-2026 Monzilla Media. All rights reserved.
36 34 */
37 35
38 36 if (!defined('ABSPATH')) die();
39 37
40 38 if (!defined('USP_WP_VERSION')) define('USP_WP_VERSION', '4.7');
41 -if (!defined('USP_VERSION')) define('USP_VERSION', '20251121');
39 +if (!defined('USP_VERSION')) define('USP_VERSION', '20260916');
42 40 if (!defined('USP_PLUGIN')) define('USP_PLUGIN', 'User Submitted Posts');
43 41 if (!defined('USP_FILE')) define('USP_FILE', plugin_basename(__FILE__));
44 42 if (!defined('USP_PATH')) define('USP_PATH', plugin_dir_path(__FILE__));
45 43 if (!defined('USP_URL')) define('USP_URL', plugin_dir_url (__FILE__));
@@ -121,10 +119,10 @@
121 119 deactivate_plugins(USP_FILE);
122 120
123 121 $msg = '<strong>'. USP_PLUGIN .'</strong> ';
124 122 $msg .= esc_html__('requires WordPress ', 'usp') . USP_WP_VERSION;
125 - $msg .= esc_html__(' or higher, and has been deactivated! ', 'usp');
126 - $msg .= esc_html__('Please return to the', 'usp') .' <a href="'. admin_url() .'">';
123 + $msg .= esc_html__(' or higher, and has been deactivated. ', 'usp');
124 + $msg .= esc_html__('Please return to the', 'usp') .' <a href="'. admin_url('plugins.php') .'">';
127 125 $msg .= esc_html__('WordPress Admin Area', 'usp') .'</a> ';
128 126 $msg .= esc_html__('to upgrade WordPress and try again.', 'usp');
129 127
130 128 wp_die($msg);
@@ -295,8 +293,12 @@
295 293
296 294
297 295 function usp_get_submitted_category() {
298 296
297 + global $usp_options;
298 +
299 + $allowed_cats = isset($usp_options['categories']) ? array_map('intval', $usp_options['categories']) : array();
300 +
299 301 $category = isset($_POST['user-submitted-category']) ? $_POST['user-submitted-category'] : '';
300 302
301 303 if (is_array($category)) {
302 304
@@ -301,20 +303,30 @@
301 303 if (is_array($category)) {
302 304
303 305 $cats = array();
304 306
305 - foreach ($category as $cat) $cats[] = sanitize_text_field($cat);
307 + foreach ($category as $cat) $cats[] = intval($cat);
306 308
309 + $cats = array_intersect($cats, $allowed_cats);
310 +
307 311 } else {
308 312
309 313 if (strpos($category, ',') !== false) {
310 314
311 - $cats = array_map('trim', explode(',', $category));
315 + $cats = array_map('intval', array_map('trim', explode(',', $category)));
312 316
317 + $cats = array_intersect($cats, $allowed_cats);
318 +
313 319 } else {
314 320
315 - $cats = sanitize_text_field($category);
321 + $cats = intval($category);
316 322
323 + if (!in_array($cats, $allowed_cats)) {
324 +
325 + $cats = isset($allowed_cats[0]) ? $allowed_cats[0] : '';
326 +
327 + }
328 +
317 329 }
318 330
319 331 }
320 332
@@ -472,24 +484,13 @@
472 484 }
473 485
474 486 if ($post_id) {
475 487
476 - if (!empty($_POST['redirect-override'])) {
477 -
478 - $redirect = $_POST['redirect-override'];
479 -
480 - $redirect = remove_query_arg(array('usp-error'), $redirect);
481 - $redirect = add_query_arg(array('usp_redirect' => '1', 'success' => 1, 'post_id' => $post_id), $redirect);
482 -
483 - } else {
484 -
485 - $redirect = $_SERVER['REQUEST_URI'];
486 -
487 - $redirect = remove_query_arg(array('usp-error'), $redirect);
488 - $redirect = add_query_arg(array('success' => 1, 'post_id' => $post_id), $redirect);
489 -
490 - }
488 + $redirect = $_SERVER['REQUEST_URI'];
491 489
490 + $redirect = remove_query_arg(array('usp-error'), $redirect);
491 + $redirect = add_query_arg(array('success' => 1, 'post_id' => $post_id), $redirect);
492 +
492 493 do_action('usp_submit_success', $redirect);
493 494
494 495 } else {
495 496
@@ -694,12 +695,12 @@
694 695 if (!empty($name) || !empty($email) || !empty($url) || !empty($ip)) {
695 696
696 697 echo '<ul style="margin-left:24px;list-style:square outside;">';
697 698
698 - if (!empty($name)) echo '<li>'. esc_html__('Submitter Name: ', 'usp') . $name .'</li>';
699 - if (!empty($email)) echo '<li>'. esc_html__('Submitter Email: ', 'usp') . $email .'</li>';
700 - if (!empty($url)) echo '<li>'. esc_html__('Submitter URL: ', 'usp') . $url .'</li>';
701 - if (!empty($ip) && !$usp_options['disable_ip_tracking']) echo '<li>'. esc_html__('Submitter IP: ', 'usp') . $ip .'</li>';
699 + if (!empty($name)) echo '<li>'. esc_html__('Submitter Name: ', 'usp') . esc_html($name) .'</li>';
700 + if (!empty($email)) echo '<li>'. esc_html__('Submitter Email: ', 'usp') . esc_html($email) .'</li>';
701 + if (!empty($url)) echo '<li>'. esc_html__('Submitter URL: ', 'usp') . esc_html($url) .'</li>';
702 + if (!empty($ip) && !$usp_options['disable_ip_tracking']) echo '<li>'. esc_html__('Submitter IP: ', 'usp') . esc_html($ip) .'</li>';
702 703
703 704 echo '</ul>';
704 705
705 706 }
@@ -1563,8 +1564,24 @@
1563 1564 return true;
1564 1565
1565 1566 }
1566 1567
1568 +function usp_post_cats($post_id) {
1569 +
1570 + $cats = '';
1571 +
1572 + foreach((get_the_category($post_id)) as $category) {
1573 +
1574 + $cats .= $category->cat_name .', ';
1575 +
1576 + }
1577 +
1578 + $cats = trim($cats, ', ');
1579 +
1580 + return $cats;
1581 +
1582 +}
1583 +
1567 1584 function usp_send_mail_alert($post_id, $title, $content, $author, $email, $url, $custom, $custom_2, $post_date) {
1568 1585
1569 1586 global $usp_options;
1570 1587
@@ -1572,8 +1589,9 @@
1572 1589
1573 1590 $blog_url = get_bloginfo('url'); // %%blog_url%%
1574 1591 $blog_name = get_bloginfo('name'); // %%blog_name%%
1575 1592 $post_url = get_permalink($post_id); // %%post_url%%
1593 + $post_cats = usp_post_cats($post_id); // %%post_cats%%
1576 1594 $admin_url = admin_url(); // %%admin_url%%
1577 1595 $post_title = $title; // %%post_title%%
1578 1596 $post_content = $content; // %%post_content%%
1579 1597 $post_author = $author; // %%post_author%%
@@ -1584,22 +1602,23 @@
1584 1602 $delete_link = usp_remote_delete_post_link($post_id); // %%delete_link%%
1585 1603
1586 1604 $patterns = array();
1587 1605
1588 - $patterns[0] = "/%%blog_url%%/";
1589 - $patterns[1] = "/%%blog_name%%/";
1590 - $patterns[2] = "/%%post_url%%/";
1591 - $patterns[3] = "/%%admin_url%%/";
1592 - $patterns[4] = "/%%post_title%%/";
1593 - $patterns[5] = "/%%post_content%%/";
1594 - $patterns[6] = "/%%post_author%%/";
1595 - $patterns[7] = "/%%user_email%%/";
1596 - $patterns[8] = "/%%user_url%%/";
1597 - $patterns[9] = "/%%edit_link%%/";
1598 - $patterns[10] = "/%%custom_field%%/";
1599 - $patterns[11] = "/%%custom_field_2%%/";
1600 - $patterns[12] = "/%%delete_link%%/";
1601 - $patterns[13] = "/%%post_date%%/";
1606 + $patterns[0] = "%%blog_url%%";
1607 + $patterns[1] = "%%blog_name%%";
1608 + $patterns[2] = "%%post_url%%";
1609 + $patterns[3] = "%%admin_url%%";
1610 + $patterns[4] = "%%post_title%%";
1611 + $patterns[5] = "%%post_content%%";
1612 + $patterns[6] = "%%post_author%%";
1613 + $patterns[7] = "%%user_email%%";
1614 + $patterns[8] = "%%user_url%%";
1615 + $patterns[9] = "%%edit_link%%";
1616 + $patterns[10] = "%%custom_field%%";
1617 + $patterns[11] = "%%custom_field_2%%";
1618 + $patterns[12] = "%%delete_link%%";
1619 + $patterns[13] = "%%post_date%%";
1620 + $patterns[14] = "%%post_cats%%";
1602 1621
1603 1622 $replacements = array();
1604 1623
1605 1624 $replacements[0] = $blog_url;
@@ -1615,19 +1634,28 @@
1615 1634 $replacements[10] = $custom;
1616 1635 $replacements[11] = $custom_2;
1617 1636 $replacements[12] = $delete_link;
1618 1637 $replacements[13] = $post_date;
1638 + $replacements[14] = $post_cats;
1619 1639
1620 1640 //
1621 1641
1622 1642 $subject_default = $blog_name .': New user-submitted post!';
1623 1643 $subject = (isset($usp_options['email_alert_subject']) && !empty($usp_options['email_alert_subject'])) ? $usp_options['email_alert_subject'] : $subject_default;
1624 - $subject = preg_replace($patterns, $replacements, $subject);
1644 + for($i = 0; $i < count($patterns); $i++) {
1645 + $pattern = isset($patterns[$i]) ? $patterns[$i] : '';
1646 + $replace = isset($replacements[$i]) ? $replacements[$i] : '';
1647 + $subject = str_replace($pattern, $replace, $subject);
1648 + }
1625 1649 $subject = apply_filters('usp_mail_subject', $subject);
1626 1650
1627 1651 $message_default = 'Hello, there is a new user-submitted post:'. "\r\n\n" . 'Title: '. $post_title . "\r\n\n" .'Visit Admin Area: '. $admin_url;
1628 1652 $message = (isset($usp_options['email_alert_message']) && !empty($usp_options['email_alert_message'])) ? $usp_options['email_alert_message'] : $message_default;
1629 - $message = preg_replace($patterns, $replacements, $message);
1653 + for($i = 0; $i < count($patterns); $i++) {
1654 + $pattern = isset($patterns[$i]) ? $patterns[$i] : '';
1655 + $replace = isset($replacements[$i]) ? $replacements[$i] : '';
1656 + $message = str_replace($pattern, $replace, $message);
1657 + }
1630 1658 $message = apply_filters('usp_mail_message', $message);
1631 1659
1632 1660 $html = isset($usp_options['usp_email_html']) ? $usp_options['usp_email_html'] : false;
1633 1661 $format = $html ? 'text/html' : 'text/plain';