| @@ -8,18 +8,16 @@ | ||
| 8 | 8 | Author URI: https://plugin-planet.com/ |
| 9 | 9 | Donate link: https://monzillamedia.com/donate.html |
| 10 | 10 | Contributors: specialk |
| 11 | 11 | Requires at least: 4.7 |
| 12 | - Tested up to: 6.9 | |
| 13 | - Stable tag: 20260110 | |
| 14 | - Version: 20260110 | |
| 12 | + Tested up to: 7.1 | |
| 13 | + Stable tag: 20260916 | |
| 14 | + Version: 20260916 | |
| 15 | 15 | Requires PHP: 5.6.20 |
| 16 | 16 | Text Domain: usp |
| 17 | 17 | Domain Path: /languages |
| 18 | 18 | License: GPL v2 or later |
| 19 | -*/ | |
| 20 | - | |
| 21 | -/* | |
| 19 | + | |
| 22 | 20 | This program is free software; you can redistribute it and/or |
| 23 | 21 | modify it under the terms of the GNU General Public License |
| 24 | 22 | as published by the Free Software Foundation; either version |
| 25 | 23 | 2 of the License, or (at your option) any later version. |
| @@ -31,15 +29,15 @@ | ||
| 31 | 29 | |
| 32 | 30 | You should have received a copy of the GNU General Public License |
| 33 | 31 | with this program. If not, visit: https://www.gnu.org/licenses/ |
| 34 | 32 | |
| 35 | - Copyright 2025 Monzilla Media. All rights reserved. | |
| 33 | + Copyright 2011-2026 Monzilla Media. All rights reserved. | |
| 36 | 34 | */ |
| 37 | 35 | |
| 38 | 36 | if (!defined('ABSPATH')) die(); |
| 39 | 37 | |
| 40 | 38 | if (!defined('USP_WP_VERSION')) define('USP_WP_VERSION', '4.7'); |
| 41 | -if (!defined('USP_VERSION')) define('USP_VERSION', '20260110'); | |
| 39 | +if (!defined('USP_VERSION')) define('USP_VERSION', '20260916'); | |
| 42 | 40 | if (!defined('USP_PLUGIN')) define('USP_PLUGIN', 'User Submitted Posts'); |
| 43 | 41 | if (!defined('USP_FILE')) define('USP_FILE', plugin_basename(__FILE__)); |
| 44 | 42 | if (!defined('USP_PATH')) define('USP_PATH', plugin_dir_path(__FILE__)); |
| 45 | 43 | if (!defined('USP_URL')) define('USP_URL', plugin_dir_url (__FILE__)); |
| @@ -121,10 +119,10 @@ | ||
| 121 | 119 | deactivate_plugins(USP_FILE); |
| 122 | 120 | |
| 123 | 121 | $msg = '<strong>'. USP_PLUGIN .'</strong> '; |
| 124 | 122 | $msg .= esc_html__('requires WordPress ', 'usp') . USP_WP_VERSION; |
| 125 | - $msg .= esc_html__(' or higher, and has been deactivated! ', 'usp'); | |
| 126 | - $msg .= esc_html__('Please return to the', 'usp') .' <a href="'. admin_url() .'">'; | |
| 123 | + $msg .= esc_html__(' or higher, and has been deactivated. ', 'usp'); | |
| 124 | + $msg .= esc_html__('Please return to the', 'usp') .' <a href="'. admin_url('plugins.php') .'">'; | |
| 127 | 125 | $msg .= esc_html__('WordPress Admin Area', 'usp') .'</a> '; |
| 128 | 126 | $msg .= esc_html__('to upgrade WordPress and try again.', 'usp'); |
| 129 | 127 | |
| 130 | 128 | wp_die($msg); |
| @@ -295,8 +293,12 @@ | ||
| 295 | 293 | |
| 296 | 294 | |
| 297 | 295 | function usp_get_submitted_category() { |
| 298 | 296 | |
| 297 | + global $usp_options; | |
| 298 | + | |
| 299 | + $allowed_cats = isset($usp_options['categories']) ? array_map('intval', $usp_options['categories']) : array(); | |
| 300 | + | |
| 299 | 301 | $category = isset($_POST['user-submitted-category']) ? $_POST['user-submitted-category'] : ''; |
| 300 | 302 | |
| 301 | 303 | if (is_array($category)) { |
| 302 | 304 | |
| @@ -301,20 +303,30 @@ | ||
| 301 | 303 | if (is_array($category)) { |
| 302 | 304 | |
| 303 | 305 | $cats = array(); |
| 304 | 306 | |
| 305 | - foreach ($category as $cat) $cats[] = sanitize_text_field($cat); | |
| 307 | + foreach ($category as $cat) $cats[] = intval($cat); | |
| 306 | 308 | |
| 309 | + $cats = array_intersect($cats, $allowed_cats); | |
| 310 | + | |
| 307 | 311 | } else { |
| 308 | 312 | |
| 309 | 313 | if (strpos($category, ',') !== false) { |
| 310 | 314 | |
| 311 | - $cats = array_map('trim', explode(',', $category)); | |
| 315 | + $cats = array_map('intval', array_map('trim', explode(',', $category))); | |
| 312 | 316 | |
| 317 | + $cats = array_intersect($cats, $allowed_cats); | |
| 318 | + | |
| 313 | 319 | } else { |
| 314 | 320 | |
| 315 | - $cats = sanitize_text_field($category); | |
| 321 | + $cats = intval($category); | |
| 316 | 322 | |
| 323 | + if (!in_array($cats, $allowed_cats)) { | |
| 324 | + | |
| 325 | + $cats = isset($allowed_cats[0]) ? $allowed_cats[0] : ''; | |
| 326 | + | |
| 327 | + } | |
| 328 | + | |
| 317 | 329 | } |
| 318 | 330 | |
| 319 | 331 | } |
| 320 | 332 | |
| @@ -683,12 +695,12 @@ | ||
| 683 | 695 | if (!empty($name) || !empty($email) || !empty($url) || !empty($ip)) { |
| 684 | 696 | |
| 685 | 697 | echo '<ul style="margin-left:24px;list-style:square outside;">'; |
| 686 | 698 | |
| 687 | - if (!empty($name)) echo '<li>'. esc_html__('Submitter Name: ', 'usp') . $name .'</li>'; | |
| 688 | - if (!empty($email)) echo '<li>'. esc_html__('Submitter Email: ', 'usp') . $email .'</li>'; | |
| 689 | - if (!empty($url)) echo '<li>'. esc_html__('Submitter URL: ', 'usp') . $url .'</li>'; | |
| 690 | - if (!empty($ip) && !$usp_options['disable_ip_tracking']) echo '<li>'. esc_html__('Submitter IP: ', 'usp') . $ip .'</li>'; | |
| 699 | + if (!empty($name)) echo '<li>'. esc_html__('Submitter Name: ', 'usp') . esc_html($name) .'</li>'; | |
| 700 | + if (!empty($email)) echo '<li>'. esc_html__('Submitter Email: ', 'usp') . esc_html($email) .'</li>'; | |
| 701 | + if (!empty($url)) echo '<li>'. esc_html__('Submitter URL: ', 'usp') . esc_html($url) .'</li>'; | |
| 702 | + if (!empty($ip) && !$usp_options['disable_ip_tracking']) echo '<li>'. esc_html__('Submitter IP: ', 'usp') . esc_html($ip) .'</li>'; | |
| 691 | 703 | |
| 692 | 704 | echo '</ul>'; |
| 693 | 705 | |
| 694 | 706 | } |
| @@ -1552,8 +1564,24 @@ | ||
| 1552 | 1564 | return true; |
| 1553 | 1565 | |
| 1554 | 1566 | } |
| 1555 | 1567 | |
| 1568 | +function usp_post_cats($post_id) { | |
| 1569 | + | |
| 1570 | + $cats = ''; | |
| 1571 | + | |
| 1572 | + foreach((get_the_category($post_id)) as $category) { | |
| 1573 | + | |
| 1574 | + $cats .= $category->cat_name .', '; | |
| 1575 | + | |
| 1576 | + } | |
| 1577 | + | |
| 1578 | + $cats = trim($cats, ', '); | |
| 1579 | + | |
| 1580 | + return $cats; | |
| 1581 | + | |
| 1582 | +} | |
| 1583 | + | |
| 1556 | 1584 | function usp_send_mail_alert($post_id, $title, $content, $author, $email, $url, $custom, $custom_2, $post_date) { |
| 1557 | 1585 | |
| 1558 | 1586 | global $usp_options; |
| 1559 | 1587 | |
| @@ -1561,8 +1589,9 @@ | ||
| 1561 | 1589 | |
| 1562 | 1590 | $blog_url = get_bloginfo('url'); // %%blog_url%% |
| 1563 | 1591 | $blog_name = get_bloginfo('name'); // %%blog_name%% |
| 1564 | 1592 | $post_url = get_permalink($post_id); // %%post_url%% |
| 1593 | + $post_cats = usp_post_cats($post_id); // %%post_cats%% | |
| 1565 | 1594 | $admin_url = admin_url(); // %%admin_url%% |
| 1566 | 1595 | $post_title = $title; // %%post_title%% |
| 1567 | 1596 | $post_content = $content; // %%post_content%% |
| 1568 | 1597 | $post_author = $author; // %%post_author%% |
| @@ -1573,22 +1602,23 @@ | ||
| 1573 | 1602 | $delete_link = usp_remote_delete_post_link($post_id); // %%delete_link%% |
| 1574 | 1603 | |
| 1575 | 1604 | $patterns = array(); |
| 1576 | 1605 | |
| 1577 | - $patterns[0] = "/%%blog_url%%/"; | |
| 1578 | - $patterns[1] = "/%%blog_name%%/"; | |
| 1579 | - $patterns[2] = "/%%post_url%%/"; | |
| 1580 | - $patterns[3] = "/%%admin_url%%/"; | |
| 1581 | - $patterns[4] = "/%%post_title%%/"; | |
| 1582 | - $patterns[5] = "/%%post_content%%/"; | |
| 1583 | - $patterns[6] = "/%%post_author%%/"; | |
| 1584 | - $patterns[7] = "/%%user_email%%/"; | |
| 1585 | - $patterns[8] = "/%%user_url%%/"; | |
| 1586 | - $patterns[9] = "/%%edit_link%%/"; | |
| 1587 | - $patterns[10] = "/%%custom_field%%/"; | |
| 1588 | - $patterns[11] = "/%%custom_field_2%%/"; | |
| 1589 | - $patterns[12] = "/%%delete_link%%/"; | |
| 1590 | - $patterns[13] = "/%%post_date%%/"; | |
| 1606 | + $patterns[0] = "%%blog_url%%"; | |
| 1607 | + $patterns[1] = "%%blog_name%%"; | |
| 1608 | + $patterns[2] = "%%post_url%%"; | |
| 1609 | + $patterns[3] = "%%admin_url%%"; | |
| 1610 | + $patterns[4] = "%%post_title%%"; | |
| 1611 | + $patterns[5] = "%%post_content%%"; | |
| 1612 | + $patterns[6] = "%%post_author%%"; | |
| 1613 | + $patterns[7] = "%%user_email%%"; | |
| 1614 | + $patterns[8] = "%%user_url%%"; | |
| 1615 | + $patterns[9] = "%%edit_link%%"; | |
| 1616 | + $patterns[10] = "%%custom_field%%"; | |
| 1617 | + $patterns[11] = "%%custom_field_2%%"; | |
| 1618 | + $patterns[12] = "%%delete_link%%"; | |
| 1619 | + $patterns[13] = "%%post_date%%"; | |
| 1620 | + $patterns[14] = "%%post_cats%%"; | |
| 1591 | 1621 | |
| 1592 | 1622 | $replacements = array(); |
| 1593 | 1623 | |
| 1594 | 1624 | $replacements[0] = $blog_url; |
| @@ -1604,19 +1634,28 @@ | ||
| 1604 | 1634 | $replacements[10] = $custom; |
| 1605 | 1635 | $replacements[11] = $custom_2; |
| 1606 | 1636 | $replacements[12] = $delete_link; |
| 1607 | 1637 | $replacements[13] = $post_date; |
| 1638 | + $replacements[14] = $post_cats; | |
| 1608 | 1639 | |
| 1609 | 1640 | // |
| 1610 | 1641 | |
| 1611 | 1642 | $subject_default = $blog_name .': New user-submitted post!'; |
| 1612 | 1643 | $subject = (isset($usp_options['email_alert_subject']) && !empty($usp_options['email_alert_subject'])) ? $usp_options['email_alert_subject'] : $subject_default; |
| 1613 | - $subject = preg_replace($patterns, $replacements, $subject); | |
| 1644 | + for($i = 0; $i < count($patterns); $i++) { | |
| 1645 | + $pattern = isset($patterns[$i]) ? $patterns[$i] : ''; | |
| 1646 | + $replace = isset($replacements[$i]) ? $replacements[$i] : ''; | |
| 1647 | + $subject = str_replace($pattern, $replace, $subject); | |
| 1648 | + } | |
| 1614 | 1649 | $subject = apply_filters('usp_mail_subject', $subject); |
| 1615 | 1650 | |
| 1616 | 1651 | $message_default = 'Hello, there is a new user-submitted post:'. "\r\n\n" . 'Title: '. $post_title . "\r\n\n" .'Visit Admin Area: '. $admin_url; |
| 1617 | 1652 | $message = (isset($usp_options['email_alert_message']) && !empty($usp_options['email_alert_message'])) ? $usp_options['email_alert_message'] : $message_default; |
| 1618 | - $message = preg_replace($patterns, $replacements, $message); | |
| 1653 | + for($i = 0; $i < count($patterns); $i++) { | |
| 1654 | + $pattern = isset($patterns[$i]) ? $patterns[$i] : ''; | |
| 1655 | + $replace = isset($replacements[$i]) ? $replacements[$i] : ''; | |
| 1656 | + $message = str_replace($pattern, $replace, $message); | |
| 1657 | + } | |
| 1619 | 1658 | $message = apply_filters('usp_mail_message', $message); |
| 1620 | 1659 | |
| 1621 | 1660 | $html = isset($usp_options['usp_email_html']) ? $usp_options['usp_email_html'] : false; |
| 1622 | 1661 | $format = $html ? 'text/html' : 'text/plain'; |