PluginProbe
User Submitted Posts – Enable Users to Submit Posts from the Front End / 20260916
User Submitted Posts – Enable Users to Submit Posts from the Front End v20260916
20260916 20260810 20260608 20230806 20230809 20230811 20230901 20230902 20230914 20231102 20240319 20240516 20240703 20241026 20250327 20250329 20251121 20251210 20260110 20260113 20260207 20260217 20260407 20260422 trunk All 59 releases
← All changes | user-submitted-posts.php +72 -33 2026011020260916 View file →
@@ -8,18 +8,16 @@
8 8 Author URI: https://plugin-planet.com/
9 9 Donate link: https://monzillamedia.com/donate.html
10 10 Contributors: specialk
11 11 Requires at least: 4.7
12 - Tested up to: 6.9
13 - Stable tag: 20260110
14 - Version: 20260110
12 + Tested up to: 7.1
13 + Stable tag: 20260916
14 + Version: 20260916
15 15 Requires PHP: 5.6.20
16 16 Text Domain: usp
17 17 Domain Path: /languages
18 18 License: GPL v2 or later
19 -*/
20 -
21 -/*
19 +
22 20 This program is free software; you can redistribute it and/or
23 21 modify it under the terms of the GNU General Public License
24 22 as published by the Free Software Foundation; either version
25 23 2 of the License, or (at your option) any later version.
@@ -31,15 +29,15 @@
31 29
32 30 You should have received a copy of the GNU General Public License
33 31 with this program. If not, visit: https://www.gnu.org/licenses/
34 32
35 - Copyright 2025 Monzilla Media. All rights reserved.
33 + Copyright 2011-2026 Monzilla Media. All rights reserved.
36 34 */
37 35
38 36 if (!defined('ABSPATH')) die();
39 37
40 38 if (!defined('USP_WP_VERSION')) define('USP_WP_VERSION', '4.7');
41 -if (!defined('USP_VERSION')) define('USP_VERSION', '20260110');
39 +if (!defined('USP_VERSION')) define('USP_VERSION', '20260916');
42 40 if (!defined('USP_PLUGIN')) define('USP_PLUGIN', 'User Submitted Posts');
43 41 if (!defined('USP_FILE')) define('USP_FILE', plugin_basename(__FILE__));
44 42 if (!defined('USP_PATH')) define('USP_PATH', plugin_dir_path(__FILE__));
45 43 if (!defined('USP_URL')) define('USP_URL', plugin_dir_url (__FILE__));
@@ -121,10 +119,10 @@
121 119 deactivate_plugins(USP_FILE);
122 120
123 121 $msg = '<strong>'. USP_PLUGIN .'</strong> ';
124 122 $msg .= esc_html__('requires WordPress ', 'usp') . USP_WP_VERSION;
125 - $msg .= esc_html__(' or higher, and has been deactivated! ', 'usp');
126 - $msg .= esc_html__('Please return to the', 'usp') .' <a href="'. admin_url() .'">';
123 + $msg .= esc_html__(' or higher, and has been deactivated. ', 'usp');
124 + $msg .= esc_html__('Please return to the', 'usp') .' <a href="'. admin_url('plugins.php') .'">';
127 125 $msg .= esc_html__('WordPress Admin Area', 'usp') .'</a> ';
128 126 $msg .= esc_html__('to upgrade WordPress and try again.', 'usp');
129 127
130 128 wp_die($msg);
@@ -295,8 +293,12 @@
295 293
296 294
297 295 function usp_get_submitted_category() {
298 296
297 + global $usp_options;
298 +
299 + $allowed_cats = isset($usp_options['categories']) ? array_map('intval', $usp_options['categories']) : array();
300 +
299 301 $category = isset($_POST['user-submitted-category']) ? $_POST['user-submitted-category'] : '';
300 302
301 303 if (is_array($category)) {
302 304
@@ -301,20 +303,30 @@
301 303 if (is_array($category)) {
302 304
303 305 $cats = array();
304 306
305 - foreach ($category as $cat) $cats[] = sanitize_text_field($cat);
307 + foreach ($category as $cat) $cats[] = intval($cat);
306 308
309 + $cats = array_intersect($cats, $allowed_cats);
310 +
307 311 } else {
308 312
309 313 if (strpos($category, ',') !== false) {
310 314
311 - $cats = array_map('trim', explode(',', $category));
315 + $cats = array_map('intval', array_map('trim', explode(',', $category)));
312 316
317 + $cats = array_intersect($cats, $allowed_cats);
318 +
313 319 } else {
314 320
315 - $cats = sanitize_text_field($category);
321 + $cats = intval($category);
316 322
323 + if (!in_array($cats, $allowed_cats)) {
324 +
325 + $cats = isset($allowed_cats[0]) ? $allowed_cats[0] : '';
326 +
327 + }
328 +
317 329 }
318 330
319 331 }
320 332
@@ -683,12 +695,12 @@
683 695 if (!empty($name) || !empty($email) || !empty($url) || !empty($ip)) {
684 696
685 697 echo '<ul style="margin-left:24px;list-style:square outside;">';
686 698
687 - if (!empty($name)) echo '<li>'. esc_html__('Submitter Name: ', 'usp') . $name .'</li>';
688 - if (!empty($email)) echo '<li>'. esc_html__('Submitter Email: ', 'usp') . $email .'</li>';
689 - if (!empty($url)) echo '<li>'. esc_html__('Submitter URL: ', 'usp') . $url .'</li>';
690 - if (!empty($ip) && !$usp_options['disable_ip_tracking']) echo '<li>'. esc_html__('Submitter IP: ', 'usp') . $ip .'</li>';
699 + if (!empty($name)) echo '<li>'. esc_html__('Submitter Name: ', 'usp') . esc_html($name) .'</li>';
700 + if (!empty($email)) echo '<li>'. esc_html__('Submitter Email: ', 'usp') . esc_html($email) .'</li>';
701 + if (!empty($url)) echo '<li>'. esc_html__('Submitter URL: ', 'usp') . esc_html($url) .'</li>';
702 + if (!empty($ip) && !$usp_options['disable_ip_tracking']) echo '<li>'. esc_html__('Submitter IP: ', 'usp') . esc_html($ip) .'</li>';
691 703
692 704 echo '</ul>';
693 705
694 706 }
@@ -1552,8 +1564,24 @@
1552 1564 return true;
1553 1565
1554 1566 }
1555 1567
1568 +function usp_post_cats($post_id) {
1569 +
1570 + $cats = '';
1571 +
1572 + foreach((get_the_category($post_id)) as $category) {
1573 +
1574 + $cats .= $category->cat_name .', ';
1575 +
1576 + }
1577 +
1578 + $cats = trim($cats, ', ');
1579 +
1580 + return $cats;
1581 +
1582 +}
1583 +
1556 1584 function usp_send_mail_alert($post_id, $title, $content, $author, $email, $url, $custom, $custom_2, $post_date) {
1557 1585
1558 1586 global $usp_options;
1559 1587
@@ -1561,8 +1589,9 @@
1561 1589
1562 1590 $blog_url = get_bloginfo('url'); // %%blog_url%%
1563 1591 $blog_name = get_bloginfo('name'); // %%blog_name%%
1564 1592 $post_url = get_permalink($post_id); // %%post_url%%
1593 + $post_cats = usp_post_cats($post_id); // %%post_cats%%
1565 1594 $admin_url = admin_url(); // %%admin_url%%
1566 1595 $post_title = $title; // %%post_title%%
1567 1596 $post_content = $content; // %%post_content%%
1568 1597 $post_author = $author; // %%post_author%%
@@ -1573,22 +1602,23 @@
1573 1602 $delete_link = usp_remote_delete_post_link($post_id); // %%delete_link%%
1574 1603
1575 1604 $patterns = array();
1576 1605
1577 - $patterns[0] = "/%%blog_url%%/";
1578 - $patterns[1] = "/%%blog_name%%/";
1579 - $patterns[2] = "/%%post_url%%/";
1580 - $patterns[3] = "/%%admin_url%%/";
1581 - $patterns[4] = "/%%post_title%%/";
1582 - $patterns[5] = "/%%post_content%%/";
1583 - $patterns[6] = "/%%post_author%%/";
1584 - $patterns[7] = "/%%user_email%%/";
1585 - $patterns[8] = "/%%user_url%%/";
1586 - $patterns[9] = "/%%edit_link%%/";
1587 - $patterns[10] = "/%%custom_field%%/";
1588 - $patterns[11] = "/%%custom_field_2%%/";
1589 - $patterns[12] = "/%%delete_link%%/";
1590 - $patterns[13] = "/%%post_date%%/";
1606 + $patterns[0] = "%%blog_url%%";
1607 + $patterns[1] = "%%blog_name%%";
1608 + $patterns[2] = "%%post_url%%";
1609 + $patterns[3] = "%%admin_url%%";
1610 + $patterns[4] = "%%post_title%%";
1611 + $patterns[5] = "%%post_content%%";
1612 + $patterns[6] = "%%post_author%%";
1613 + $patterns[7] = "%%user_email%%";
1614 + $patterns[8] = "%%user_url%%";
1615 + $patterns[9] = "%%edit_link%%";
1616 + $patterns[10] = "%%custom_field%%";
1617 + $patterns[11] = "%%custom_field_2%%";
1618 + $patterns[12] = "%%delete_link%%";
1619 + $patterns[13] = "%%post_date%%";
1620 + $patterns[14] = "%%post_cats%%";
1591 1621
1592 1622 $replacements = array();
1593 1623
1594 1624 $replacements[0] = $blog_url;
@@ -1604,19 +1634,28 @@
1604 1634 $replacements[10] = $custom;
1605 1635 $replacements[11] = $custom_2;
1606 1636 $replacements[12] = $delete_link;
1607 1637 $replacements[13] = $post_date;
1638 + $replacements[14] = $post_cats;
1608 1639
1609 1640 //
1610 1641
1611 1642 $subject_default = $blog_name .': New user-submitted post!';
1612 1643 $subject = (isset($usp_options['email_alert_subject']) && !empty($usp_options['email_alert_subject'])) ? $usp_options['email_alert_subject'] : $subject_default;
1613 - $subject = preg_replace($patterns, $replacements, $subject);
1644 + for($i = 0; $i < count($patterns); $i++) {
1645 + $pattern = isset($patterns[$i]) ? $patterns[$i] : '';
1646 + $replace = isset($replacements[$i]) ? $replacements[$i] : '';
1647 + $subject = str_replace($pattern, $replace, $subject);
1648 + }
1614 1649 $subject = apply_filters('usp_mail_subject', $subject);
1615 1650
1616 1651 $message_default = 'Hello, there is a new user-submitted post:'. "\r\n\n" . 'Title: '. $post_title . "\r\n\n" .'Visit Admin Area: '. $admin_url;
1617 1652 $message = (isset($usp_options['email_alert_message']) && !empty($usp_options['email_alert_message'])) ? $usp_options['email_alert_message'] : $message_default;
1618 - $message = preg_replace($patterns, $replacements, $message);
1653 + for($i = 0; $i < count($patterns); $i++) {
1654 + $pattern = isset($patterns[$i]) ? $patterns[$i] : '';
1655 + $replace = isset($replacements[$i]) ? $replacements[$i] : '';
1656 + $message = str_replace($pattern, $replace, $message);
1657 + }
1619 1658 $message = apply_filters('usp_mail_message', $message);
1620 1659
1621 1660 $html = isset($usp_options['usp_email_html']) ? $usp_options['usp_email_html'] : false;
1622 1661 $format = $html ? 'text/html' : 'text/plain';