PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.38
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.38
1.2.73 1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.20 1.0.21 1.0.22 All 173 releases
← All changes | includes/class-forms.php +82 -144 1.2.631.2.38 View file →
@@ -102,26 +102,27 @@
102 102 $processed = true;
103 103 }
104 104
105 105 if ( $processed ) {
106 +
106 107 if ( is_wp_error( $errors ) ) {
107 - aui()->alert(
108 - array(
109 - 'type' => 'error',
110 - 'content' => wp_kses_post( $errors->get_error_message() )
111 - ),
112 - true
113 - );
114 - } else if ( $redirect ) {
108 + echo aui()->alert(
109 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
110 + 'type' => 'error',
111 + 'class' => 'text-center',
112 + 'content' => wp_kses_post( $errors->get_error_message() ),
113 + )
114 + );
115 + } elseif ( $redirect ) {
115 116 wp_safe_redirect( $redirect );
116 117 exit();
117 - } else {
118 - aui()->alert(
119 - array(
120 - 'type' => 'success',
121 - 'content' => wp_kses_post( $message )
122 - ),
123 - true
118 + } else {
119 + echo aui()->alert(
120 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
121 + 'type' => 'success',
122 + 'class' => 'text-center',
123 + 'content' => wp_kses_post( $message ),
124 + )
124 125 );
125 126 }
126 127 }
127 128
@@ -195,9 +196,8 @@
195 196 * @since 1.0.0
196 197 */
197 198 public function process_image_crop( $data = array(), $type = 'avatar', $unlink_prev_img = false ) {
198 199 global $wpdb;
199 -
200 200 if ( ! is_user_logged_in() ) {
201 201 return false;
202 202 }
203 203
@@ -204,29 +204,8 @@
204 204 if ( empty( $_POST['uwp_crop_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_crop_nonce'], 'uwp_crop_nonce_' . $type ) ) {
205 205 return;
206 206 }
207 207
208 - $image_url = ! empty( $data['uwp_crop'] ) ? esc_url( $data['uwp_crop'] ) : '';
209 -
210 - if ( empty( $image_url ) ) {
211 - return new WP_Error( 'empty_image', __( 'Upload valid image.', 'userswp' ) );
212 - }
213 -
214 - // Ensure we have a valid URL with an allowed meme type.
215 - $image_url = $this->normalize_url( $image_url );
216 -
217 - $content_url = str_replace( array( 'https://', 'http://' ) , '', untrailingslashit( WP_CONTENT_URL ) );
218 - $_image_url = str_replace( array( 'https://', 'http://' ), '', $image_url );
219 - if ( strpos( $_image_url, $content_url ) !== 0 ) {
220 - return new WP_Error( 'invalid_image', __( 'Invalid image url.', 'userswp' ) );
221 - }
222 -
223 - $filetype = wp_check_filetype( $image_url );
224 -
225 - if ( empty( $filetype['ext'] ) ) {
226 - return new WP_Error( 'invalid_image', __( 'Invalid image type.', 'userswp' ) );
227 - }
228 -
229 208 // If is current user's profile (profile.php)
230 209 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
231 210 $user_id = get_current_user_id();
232 211 // If is another user's profile page
@@ -236,8 +215,21 @@
236 215 } else {
237 216 $user_id = get_current_user_id();
238 217 }
239 218
219 + // Ensure we have a valid URL with an allowed meme type.
220 + $image_url = $this->normalize_url( esc_url( $data['uwp_crop'] ) );
221 + $filetype = wp_check_filetype( $image_url );
222 +
223 + $errors = new WP_Error();
224 + if ( empty( $image_url ) || empty( $filetype['ext'] ) ) {
225 + $errors->add( 'something_wrong', __( 'Something went wrong. Please contact site admin.', 'userswp' ) );
226 + }
227 +
228 + if ( $errors->has_errors() ) {
229 + return $errors;
230 + }
231 +
240 232 // Retrieve current thumbnail.
241 233 $current_field = 'avatar' === $type ? 'avatar_thumb' : 'banner_thumb';
242 234 $current_thumbnail = $this->normalize_url( uwp_get_usermeta( $user_id, $current_field, '' ) );
243 235 $thumb_postfix = '_uwp_' . $type . '_thumb';
@@ -260,14 +252,13 @@
260 252 $ext = $filetype['ext']; // to get extension
261 253 $name = sanitize_file_name( pathinfo( $image_path, PATHINFO_FILENAME ) ); //file name without extension
262 254 $thumb_image_name = $name . $thumb_postfix . '.' . $ext;
263 255 $thumb_image_location = str_replace( $name . '.' . $ext, $thumb_image_name, $image_path );
264 -
265 256 //Get the new coordinates to crop the image.
266 - $x = $data['uwpx'];
267 - $y = $data['uwpy'];
268 - $w = $data['uwpw'];
269 - $h = $data['uwph'];
257 + $x = $data['x'];
258 + $y = $data['y'];
259 + $w = $data['w'];
260 + $h = $data['h'];
270 261 //Scale the image based on cropped width setting
271 262 $scale = $full_width / $w;
272 263 //$scale = 1; // no scaling
273 264
@@ -327,11 +318,8 @@
327 318 *
328 319 */
329 320 public function normalize_url( $url ) {
330 321
331 - if ( empty( $url ) ) {
332 - return '';
333 - }
334 322 // Normalize.
335 323 $url = wp_normalize_path( $url );
336 324
337 325 // Remove query vars.
@@ -479,10 +467,10 @@
479 467 }
480 468 } elseif ( ! empty( $notice ) ) {
481 469 echo wp_kses_post( $notice );
482 470 }
483 - }
484 - }
471 +}
472 +}
485 473
486 474 if ( $type == 'change' ) {
487 475 $user_id = get_current_user_id();
488 476 $password_nag = get_user_option( 'default_password_nag', $user_id );
@@ -535,15 +523,9 @@
535 523 if ( isset( $data['uwp_register_hp'] ) && '' != $data['uwp_register_hp'] ) {
536 524 wp_die( esc_html__( 'No spam please!', 'userswp' ) );
537 525 }
538 526
539 - $form_id = 1;
540 -
541 - if ( ! empty( $data['uwp_register_form_id'] ) ) {
542 - $form_id = (int) $data['uwp_register_form_id'];
543 - }
544 -
545 - if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce-' . $form_id ) ) {
527 + if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce' ) ) {
546 528 $message = aui()->alert(
547 529 array(
548 530 'type' => 'error',
549 531 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
@@ -715,24 +697,8 @@
715 697 'last_name' => esc_attr( $last_name ),
716 698 'user_url' => esc_url_raw( $user_url ),
717 699 );
718 700
719 - // Set user role by form.
720 - $user_role = uwp_get_register_form_by( $form_id, 'user_role' );
721 -
722 - if ( ! empty( $user_role ) ) {
723 - $user_roles = uwp_get_user_roles();
724 - $chosen_role = strtolower( $user_role );
725 -
726 - if ( ! empty( $user_roles ) ) {
727 - $wp_roles = wp_roles();
728 -
729 - if ( $wp_roles->is_role( $chosen_role ) && in_array( $chosen_role, array_keys( $user_roles ) ) ) {
730 - $args['role'] = $chosen_role;
731 - }
732 - }
733 - }
734 -
735 701 $user_id = wp_insert_user( $args );
736 702
737 703 if ( is_wp_error( $user_id ) ) {
738 704 $message = aui()->alert(
@@ -751,13 +717,31 @@
751 717 }
752 718
753 719 $result = apply_filters( 'uwp_before_extra_fields_save', $result, 'register', $user_id );
754 720
755 - // Save user form id.
756 - if ( ! empty( $data['uwp_register_form_id'] ) ) {
721 + $form_id = 1;
722 +
723 + if ( isset( $data['uwp_register_form_id'] ) && ! empty( $data['uwp_register_form_id'] ) ) {
757 724 update_user_meta( $user_id, '_uwp_register_form_id', (int) $data['uwp_register_form_id'] );
725 + $form_id = (int) $data['uwp_register_form_id'];
758 726 }
759 727
728 + $user_role = uwp_get_register_form_by( $form_id, 'user_role' );
729 +
730 + if ( isset( $user_role ) && ! empty( $user_role ) ) {
731 + $user_roles = uwp_get_user_roles();
732 + $chosen_role = strtolower( $user_role );
733 + if ( ! empty( $user_roles ) ) {
734 + $wp_roles = wp_roles();
735 + if ( $wp_roles->is_role( $chosen_role ) && in_array( $chosen_role, array_keys( $user_roles ) ) ) {
736 + $new_user = get_userdata( $user_id );
737 + if ( $new_user ) {
738 + $new_user->set_role( $chosen_role );
739 + }
740 + }
741 + }
742 + }
743 +
760 744 $save_result = $this->save_user_extra_fields( $user_id, $result, 'register' );
761 745
762 746 $save_result = apply_filters( 'uwp_after_extra_fields_save', $save_result, $result, 'register', $user_id );
763 747
@@ -1674,21 +1658,12 @@
1674 1658
1675 1659 // make sure user account is active before account reset
1676 1660 $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true );
1677 1661 if ( $mod_value == 'email_unconfirmed' ) {
1678 - $resend_link = uwp_get_forgot_page_url();
1679 - $resend_link = add_query_arg(
1680 - array(
1681 - 'user_id' => $user_data->ID,
1682 - 'action' => 'uwp_resend',
1683 - '_nonce' => wp_create_nonce('uwp_resend'),
1684 - ),
1685 - $resend_link
1686 - );
1687 1662 $message = aui()->alert(
1688 1663 array(
1689 1664 'type' => 'error',
1690 - 'content' => sprintf(__('Your account is not activated yet. Please activate your account first. <a href="%s">Resend</a>.', 'userswp'), $resend_link),
1665 + 'content' => __( 'Your account is not activated yet. Please activate your account first.', 'userswp' ),
1691 1666 )
1692 1667 );
1693 1668 if ( wp_doing_ajax() ) {
1694 1669 wp_send_json_error( $message );
@@ -1693,8 +1668,9 @@
1693 1668 if ( wp_doing_ajax() ) {
1694 1669 wp_send_json_error( $message );
1695 1670 } else {
1696 1671 $uwp_notices[] = array( 'forgot' => $message );
1672 +
1697 1673 return;
1698 1674 }
1699 1675 }
1700 1676
@@ -2257,81 +2233,46 @@
2257 2233 * @package userswp
2258 2234 * @since 1.0.0
2259 2235 */
2260 2236 public function upload_file_remove() {
2261 - global $wpdb;
2262 -
2263 2237 check_ajax_referer( 'uwp_basic_nonce', 'security' );
2264 2238
2265 - // Check user logged in.
2266 - if ( ! is_user_logged_in() ) {
2267 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Access denied!', 'userswp' ) ) );
2268 - wp_send_json_error( array( 'message' => $message ) );
2269 - }
2270 -
2239 + $htmlvar = esc_sql( strip_tags( $_POST['htmlvar'] ) );
2271 2240 $user_id = ! empty( $_POST['uid'] ) ? absint( $_POST['uid'] ) : 0;
2272 - $htmlvar = ! empty( $_POST['htmlvar'] ) ? sanitize_key( $_POST['htmlvar'] ) : '';
2273 2241
2274 - if ( empty( $user_id ) || empty( $htmlvar ) ) {
2275 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid data!', 'userswp' ) ) );
2276 - wp_send_json_error( array( 'message' => $message ) );
2242 + if ( empty( $user_id ) ) {
2243 + wp_die( -1 );
2277 2244 }
2278 2245
2279 - // Validate the user / admin.
2280 - if ( ! ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) {
2281 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid access!', 'userswp' ) ) );
2282 - wp_send_json_error( array( 'message' => $message ) );
2246 + if ( ! ( is_user_logged_in() && ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) ) {
2247 + wp_send_json_error( __( 'Invalid access!', 'userswp' ) );
2283 2248 }
2284 2249
2250 + // Remove file
2285 2251 if ( $htmlvar == 'banner_thumb' ) {
2286 - $field_key = 'banner';
2252 + $file = uwp_get_usermeta( $user_id, 'banner_thumb' );
2287 2253 $type = 'banner';
2288 - } else if ( $htmlvar == 'avatar_thumb' ) {
2289 - $field_key = 'avatar';
2254 + } elseif ( $htmlvar == 'avatar_thumb' ) {
2255 + $file = uwp_get_usermeta( $user_id, 'avatar_thumb' );
2290 2256 $type = 'avatar';
2291 2257 } else {
2292 - $field_key = $htmlvar;
2258 + $file = '';
2293 2259 $type = '';
2294 2260 }
2295 2261
2296 - $field = $wpdb->get_row( $wpdb->prepare( "SELECT * FROM " . uwp_get_table_prefix() . "uwp_form_fields WHERE htmlvar_name = %s LIMIT 1", $field_key ) );
2297 -
2298 - // Check field exists.
2299 - if ( empty( $field ) ) {
2300 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field!', 'userswp' ) ) );
2301 - wp_send_json_error( array( 'message' => $message ) );
2302 - }
2303 -
2304 - // Validate field access.
2305 - if ( ! empty( $field->for_admin_use ) && ! current_user_can( 'manage_options' ) ) {
2306 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'You are not allowed to perform this action!', 'userswp' ) ) );
2307 - wp_send_json_error( array( 'message' => $message ) );
2308 - }
2309 -
2310 - if ( ! in_array( $field->field_type, array( 'file', 'image' ) ) ) {
2311 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field type!', 'userswp' ) ) );
2312 - wp_send_json_error( array( 'message' => $message ) );
2313 - }
2314 -
2315 - $value = uwp_get_usermeta( $user_id, $htmlvar );
2316 -
2317 2262 uwp_update_usermeta( $user_id, $htmlvar, '' );
2318 2263
2319 - if ( $value ) {
2264 + if ( $file ) {
2320 2265 $uploads = wp_upload_dir();
2321 2266 $upload_path = $uploads['basedir'];
2322 - $unlink_file = untrailingslashit( $upload_path ) . '/' . ltrim( $value, '/' );
2267 + $unlink_file = untrailingslashit( $upload_path ) . '/' . ltrim( $file, '/' );
2323 2268
2324 2269 if ( is_file( $unlink_file ) && file_exists( $unlink_file ) ) {
2325 2270 @unlink( $unlink_file );
2271 + $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_file );
2326 2272
2327 - // For avatar/banner, also remove the original (non-thumb) file.
2328 - if ( $type ) {
2329 - $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_file );
2330 -
2331 - if ( is_file( $unlink_ori_file ) && file_exists( $unlink_ori_file ) ) {
2332 - @unlink( $unlink_ori_file );
2333 - }
2273 + if ( is_file( $unlink_ori_file ) && file_exists( $unlink_ori_file ) ) {
2274 + @unlink( $unlink_ori_file );
2334 2275 }
2335 2276 }
2336 2277 }
2337 2278
@@ -2577,9 +2518,9 @@
2577 2518 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2578 2519 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2579 2520 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2580 2521 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2581 - 'input_group_right' => '<div class="input-group-text px-2 bg-transparent border-0x" onclick="jQuery(this).parent().parent().find(\'input\').val(\'\');"><i class="fas fa-times uwp-search-input-label-clear text-muted c-pointer" title="' . esc_attr__( 'Clear field', 'userswp' ) . '" ></i></div>',
2522 + 'input_group_right' => '<div class="input-group-text px-2 bg-transparent border-0x" onclick="jQuery(this).parent().parent().find(\'input\').val(\'\');"><i class="fas fa-times uwp-search-input-label-clear text-muted c-pointer" title="' . esc_attr__( 'Clear field', 'uwp-search' ) . '" ></i></div>',
2582 2523 )
2583 2524 );
2584 2525 } else {
2585 2526 ?>
@@ -4365,9 +4306,9 @@
4365 4306 // If no html then we run the standard output.
4366 4307 if ( empty( $html ) ) {
4367 4308
4368 4309 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4369 - $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds margin so we remove ours
4310 + $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds marginso we remove ours
4370 4311 $bs_sr_only = $design_style ? 'sr-only' : '';
4371 4312 $bs_form_control = $design_style ? 'form-control' : '';
4372 4313
4373 4314 ob_start(); // Start buffering;
@@ -4930,13 +4871,13 @@
4930 4871 function (event) {
4931 4872 var $form = $(this).closest('form');
4932 4873 if( ! $form.hasClass('uwp-login-form') ) {
4933 4874 uwp_checkPasswordStrength(
4934 - $form.find('input[name=password]'),
4935 - $form.find('input[name=confirm_password]'),
4936 - $form.find('#uwp-password-strength'),
4937 - $form.find('button[type="submit"], input[type="submit"]'),
4938 - ['black', 'listed', 'word']
4875 + $('input[name=password]', $form), // First password field
4876 + $('input[name=confirm_password]', $form), // Second password field
4877 + $('#uwp-password-strength', $form), // Strength meter
4878 + $('input[type=submit]', $form), // Submit button
4879 + ['black', 'listed', 'word'] // Blacklisted words
4939 4880 );
4940 4881 }
4941 4882 }
4942 4883 );
@@ -4963,15 +4904,12 @@
4963 4904 public function ajax_forgot_password_form() {
4964 4905
4965 4906 // add the modal error container
4966 4907 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
4967 - $args = array(
4968 - 'form_title' => '',
4969 - 'css_class' => ''
4970 - );
4908 +
4971 4909 // get the form
4972 4910 ob_start();
4973 - uwp_get_template( 'bootstrap/forgot.php', $args );
4911 + uwp_get_template( 'bootstrap/forgot.php' );
4974 4912 $form = ob_get_clean();
4975 4913
4976 4914 // bs5
4977 4915 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {