PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.38
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.38
1.2.73 1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.20 1.0.21 1.0.22 All 173 releases
← All changes | includes/class-forms.php +141 -339 1.2.721.2.38 View file →
@@ -102,26 +102,27 @@
102 102 $processed = true;
103 103 }
104 104
105 105 if ( $processed ) {
106 +
106 107 if ( is_wp_error( $errors ) ) {
107 - aui()->alert(
108 - array(
109 - 'type' => 'error',
110 - 'content' => wp_kses_post( $errors->get_error_message() )
111 - ),
112 - true
113 - );
114 - } else if ( $redirect ) {
108 + echo aui()->alert(
109 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
110 + 'type' => 'error',
111 + 'class' => 'text-center',
112 + 'content' => wp_kses_post( $errors->get_error_message() ),
113 + )
114 + );
115 + } elseif ( $redirect ) {
115 116 wp_safe_redirect( $redirect );
116 117 exit();
117 - } else {
118 - aui()->alert(
119 - array(
120 - 'type' => 'success',
121 - 'content' => wp_kses_post( $message )
122 - ),
123 - true
118 + } else {
119 + echo aui()->alert(
120 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
121 + 'type' => 'success',
122 + 'class' => 'text-center',
123 + 'content' => wp_kses_post( $message ),
124 + )
124 125 );
125 126 }
126 127 }
127 128
@@ -195,9 +196,8 @@
195 196 * @since 1.0.0
196 197 */
197 198 public function process_image_crop( $data = array(), $type = 'avatar', $unlink_prev_img = false ) {
198 199 global $wpdb;
199 -
200 200 if ( ! is_user_logged_in() ) {
201 201 return false;
202 202 }
203 203
@@ -204,29 +204,8 @@
204 204 if ( empty( $_POST['uwp_crop_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_crop_nonce'], 'uwp_crop_nonce_' . $type ) ) {
205 205 return;
206 206 }
207 207
208 - $image_url = ! empty( $data['uwp_crop'] ) ? esc_url( $data['uwp_crop'] ) : '';
209 -
210 - if ( empty( $image_url ) ) {
211 - return new WP_Error( 'empty_image', __( 'Upload valid image.', 'userswp' ) );
212 - }
213 -
214 - // Ensure we have a valid URL with an allowed meme type.
215 - $image_url = $this->normalize_url( $image_url );
216 -
217 - $content_url = str_replace( array( 'https://', 'http://' ) , '', untrailingslashit( WP_CONTENT_URL ) );
218 - $_image_url = str_replace( array( 'https://', 'http://' ), '', $image_url );
219 - if ( strpos( $_image_url, $content_url ) !== 0 ) {
220 - return new WP_Error( 'invalid_image', __( 'Invalid image url.', 'userswp' ) );
221 - }
222 -
223 - $filetype = wp_check_filetype( $image_url );
224 -
225 - if ( empty( $filetype['ext'] ) ) {
226 - return new WP_Error( 'invalid_image', __( 'Invalid image type.', 'userswp' ) );
227 - }
228 -
229 208 // If is current user's profile (profile.php)
230 209 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
231 210 $user_id = get_current_user_id();
232 211 // If is another user's profile page
@@ -236,8 +215,21 @@
236 215 } else {
237 216 $user_id = get_current_user_id();
238 217 }
239 218
219 + // Ensure we have a valid URL with an allowed meme type.
220 + $image_url = $this->normalize_url( esc_url( $data['uwp_crop'] ) );
221 + $filetype = wp_check_filetype( $image_url );
222 +
223 + $errors = new WP_Error();
224 + if ( empty( $image_url ) || empty( $filetype['ext'] ) ) {
225 + $errors->add( 'something_wrong', __( 'Something went wrong. Please contact site admin.', 'userswp' ) );
226 + }
227 +
228 + if ( $errors->has_errors() ) {
229 + return $errors;
230 + }
231 +
240 232 // Retrieve current thumbnail.
241 233 $current_field = 'avatar' === $type ? 'avatar_thumb' : 'banner_thumb';
242 234 $current_thumbnail = $this->normalize_url( uwp_get_usermeta( $user_id, $current_field, '' ) );
243 235 $thumb_postfix = '_uwp_' . $type . '_thumb';
@@ -260,14 +252,13 @@
260 252 $ext = $filetype['ext']; // to get extension
261 253 $name = sanitize_file_name( pathinfo( $image_path, PATHINFO_FILENAME ) ); //file name without extension
262 254 $thumb_image_name = $name . $thumb_postfix . '.' . $ext;
263 255 $thumb_image_location = str_replace( $name . '.' . $ext, $thumb_image_name, $image_path );
264 -
265 256 //Get the new coordinates to crop the image.
266 - $x = $data['uwpx'];
267 - $y = $data['uwpy'];
268 - $w = $data['uwpw'];
269 - $h = $data['uwph'];
257 + $x = $data['x'];
258 + $y = $data['y'];
259 + $w = $data['w'];
260 + $h = $data['h'];
270 261 //Scale the image based on cropped width setting
271 262 $scale = $full_width / $w;
272 263 //$scale = 1; // no scaling
273 264
@@ -327,11 +318,8 @@
327 318 *
328 319 */
329 320 public function normalize_url( $url ) {
330 321
331 - if ( empty( $url ) ) {
332 - return '';
333 - }
334 322 // Normalize.
335 323 $url = wp_normalize_path( $url );
336 324
337 325 // Remove query vars.
@@ -360,20 +348,22 @@
360 348 if ( ! is_user_logged_in() ) {
361 349 return false;
362 350 }
363 351
352 + if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type ) ) {
353 + return;
354 + }
355 +
364 356 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
365 357 $user_id = get_current_user_id();
366 - } elseif ( is_admin() && current_user_can( 'manage_options' ) && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
358 + // If is another user's profile page
359 + } elseif ( is_admin() && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
367 360 $user_id = absint( $_GET['user_id'] );
361 + // Otherwise something is wrong.
368 362 } else {
369 363 $user_id = get_current_user_id();
370 364 }
371 365
372 - if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type . '_' . $user_id ) ) {
373 - return;
374 - }
375 -
376 366 $errors = new WP_Error();
377 367 if ( empty( $user_id ) ) {
378 368 $errors->add( 'something_wrong', __( 'Something went wrong. Please try again.', 'userswp' ) );
379 369 }
@@ -477,10 +467,10 @@
477 467 }
478 468 } elseif ( ! empty( $notice ) ) {
479 469 echo wp_kses_post( $notice );
480 470 }
481 - }
482 - }
471 +}
472 +}
483 473
484 474 if ( $type == 'change' ) {
485 475 $user_id = get_current_user_id();
486 476 $password_nag = get_user_option( 'default_password_nag', $user_id );
@@ -533,15 +523,9 @@
533 523 if ( isset( $data['uwp_register_hp'] ) && '' != $data['uwp_register_hp'] ) {
534 524 wp_die( esc_html__( 'No spam please!', 'userswp' ) );
535 525 }
536 526
537 - $form_id = 1;
538 -
539 - if ( ! empty( $data['uwp_register_form_id'] ) ) {
540 - $form_id = (int) $data['uwp_register_form_id'];
541 - }
542 -
543 - if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce-' . $form_id ) ) {
527 + if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce' ) ) {
544 528 $message = aui()->alert(
545 529 array(
546 530 'type' => 'error',
547 531 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
@@ -713,24 +697,8 @@
713 697 'last_name' => esc_attr( $last_name ),
714 698 'user_url' => esc_url_raw( $user_url ),
715 699 );
716 700
717 - // Set user role by form.
718 - $user_role = uwp_get_register_form_by( $form_id, 'user_role' );
719 -
720 - if ( ! empty( $user_role ) ) {
721 - $user_roles = uwp_get_user_roles();
722 - $chosen_role = strtolower( $user_role );
723 -
724 - if ( ! empty( $user_roles ) ) {
725 - $wp_roles = wp_roles();
726 -
727 - if ( $wp_roles->is_role( $chosen_role ) && in_array( $chosen_role, array_keys( $user_roles ) ) ) {
728 - $args['role'] = $chosen_role;
729 - }
730 - }
731 - }
732 -
733 701 $user_id = wp_insert_user( $args );
734 702
735 703 if ( is_wp_error( $user_id ) ) {
736 704 $message = aui()->alert(
@@ -749,13 +717,31 @@
749 717 }
750 718
751 719 $result = apply_filters( 'uwp_before_extra_fields_save', $result, 'register', $user_id );
752 720
753 - // Save user form id.
754 - if ( ! empty( $data['uwp_register_form_id'] ) ) {
721 + $form_id = 1;
722 +
723 + if ( isset( $data['uwp_register_form_id'] ) && ! empty( $data['uwp_register_form_id'] ) ) {
755 724 update_user_meta( $user_id, '_uwp_register_form_id', (int) $data['uwp_register_form_id'] );
725 + $form_id = (int) $data['uwp_register_form_id'];
756 726 }
757 727
728 + $user_role = uwp_get_register_form_by( $form_id, 'user_role' );
729 +
730 + if ( isset( $user_role ) && ! empty( $user_role ) ) {
731 + $user_roles = uwp_get_user_roles();
732 + $chosen_role = strtolower( $user_role );
733 + if ( ! empty( $user_roles ) ) {
734 + $wp_roles = wp_roles();
735 + if ( $wp_roles->is_role( $chosen_role ) && in_array( $chosen_role, array_keys( $user_roles ) ) ) {
736 + $new_user = get_userdata( $user_id );
737 + if ( $new_user ) {
738 + $new_user->set_role( $chosen_role );
739 + }
740 + }
741 + }
742 + }
743 +
758 744 $save_result = $this->save_user_extra_fields( $user_id, $result, 'register' );
759 745
760 746 $save_result = apply_filters( 'uwp_after_extra_fields_save', $save_result, $result, 'register', $user_id );
761 747
@@ -1175,11 +1161,8 @@
1175 1161 global $wp2fa;
1176 1162 if ( wp_doing_ajax() && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1177 1163 remove_action( 'wp_login', array( $wp2fa->login, 'wp_login' ), 20 );
1178 1164 }
1179 - if ( wp_doing_ajax() && class_exists( '\WP2FA\Authenticator\Login' ) ) {
1180 - remove_action( 'wp_login', array( 'WP2FA\Authenticator\Login', 'wp_login' ), 20 );
1181 - }
1182 1165
1183 1166 $user = wp_signon(
1184 1167 array(
1185 1168 'user_login' => $result['username'],
@@ -1188,14 +1171,10 @@
1188 1171 )
1189 1172 );
1190 1173
1191 1174 add_action( 'authenticate', 'gglcptch_login_check', 21, 1 );
1192 - if ( wp_doing_ajax() && class_exists( '\WP2FA\Authenticator\Login' ) ) {
1193 - add_action( 'wp_login', array( 'WP2FA\Authenticator\Login', 'wp_login' ), 20, 2 );
1194 - }
1195 1175
1196 - $wp2fa_available = ( isset( $wp2fa ) && ! empty( $wp2fa ) ) || class_exists( '\WP2FA\Authenticator\Login' );
1197 - if ( wp_doing_ajax() && ! is_wp_error( $user ) && $wp2fa_available ) {
1176 + if ( wp_doing_ajax() && ! is_wp_error( $user ) && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1198 1177
1199 1178 $two_fa = $this->check_2fa( $user );
1200 1179 if ( isset( $two_fa ) && ! empty( $two_fa ) ) {
1201 1180 if ( is_wp_error( $two_fa ) ) {
@@ -1285,12 +1264,9 @@
1285 1264
1286 1265 return $errors;
1287 1266 }
1288 1267
1289 - $provider = $this->get_wp2fa_provider_for_user( $user );
1290 - if ( empty( $provider ) ) {
1291 - return;
1292 - }
1268 + $provider = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1293 1269
1294 1270 ob_start();
1295 1271 ?>
1296 1272
@@ -1341,9 +1317,9 @@
1341 1317 echo aui()->input(
1342 1318 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1343 1319 'type' => 'tel',
1344 1320 'id' => 'authcode',
1345 - 'name' => 'authcode',
1321 + 'name' => 'wp-2fa-email-code',
1346 1322 'placeholder' => esc_attr__( 'Verification Code', 'userswp' ),
1347 1323 'value' => '',
1348 1324 'label' => esc_html__( 'Verification Code', 'userswp' ),
1349 1325 'extra_attributes' => array(
@@ -1378,9 +1354,9 @@
1378 1354 </form>
1379 1355 </div>
1380 1356
1381 1357 <?php
1382 - $codes_remaining = $this->get_wp2fa_backup_codes_remaining( $user );
1358 + $codes_remaining = \WP2FA\Authenticator\Backup_Codes::codes_remaining_for_user( $user );
1383 1359 if ( isset( $codes_remaining ) && $codes_remaining > 0 ) {
1384 1360 ?>
1385 1361 <div class="uwp-2fa-methods-wrap" style="display:none;">
1386 1362 <form name="validate_2fa_backup_codes_form" id="validate_2fa_backup_codes_form"
@@ -1436,76 +1412,9 @@
1436 1412
1437 1413 return ob_get_clean();
1438 1414 }
1439 1415
1440 - public function get_wp2fa_provider_for_user( $user ) {
1441 - if ( class_exists( '\WP2FA\Authenticator\Login' ) && method_exists( '\WP2FA\Authenticator\Login', 'get_available_providers_for_user' ) ) {
1442 - $provider = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1443 - if ( is_array( $provider ) ) {
1444 - $provider = key( $provider );
1445 - }
1446 -
1447 - return $provider;
1448 - }
1449 -
1450 - if ( class_exists( '\WP2FA\Admin\Helpers\User_Helper' ) && method_exists( '\WP2FA\Admin\Helpers\User_Helper', 'get_enabled_method_for_user' ) ) {
1451 - return \WP2FA\Admin\Helpers\User_Helper::get_enabled_method_for_user( $user );
1452 - }
1453 -
1454 - return '';
1455 - }
1456 -
1457 - public function get_wp2fa_backup_codes_remaining( $user ) {
1458 - if ( class_exists( '\WP2FA\Methods\Backup_Codes' ) && method_exists( '\WP2FA\Methods\Backup_Codes', 'codes_remaining_for_user' ) ) {
1459 - return \WP2FA\Methods\Backup_Codes::codes_remaining_for_user( $user );
1460 - }
1461 -
1462 - if ( class_exists( '\WP2FA\Authenticator\Backup_Codes' ) && method_exists( '\WP2FA\Authenticator\Backup_Codes', 'codes_remaining_for_user' ) ) {
1463 - return \WP2FA\Authenticator\Backup_Codes::codes_remaining_for_user( $user );
1464 - }
1465 -
1466 - return 0;
1467 - }
1468 -
1469 - public function validate_wp2fa_totp_authentication( $user ) {
1470 - if ( class_exists( '\WP2FA\Methods\TOTP' ) && method_exists( '\WP2FA\Methods\TOTP', 'validate_totp_authentication' ) ) {
1471 - return \WP2FA\Methods\TOTP::validate_totp_authentication( $user );
1472 - }
1473 -
1474 - if ( class_exists( '\WP2FA\Authenticator\Login' ) && method_exists( '\WP2FA\Authenticator\Login', 'validate_totp_authentication' ) ) {
1475 - return \WP2FA\Authenticator\Login::validate_totp_authentication( $user );
1476 - }
1477 -
1478 - return false;
1479 - }
1480 -
1481 - public function validate_wp2fa_email_authentication( $user ) {
1482 - if ( class_exists( '\WP2FA\Authenticator\Login' ) && method_exists( '\WP2FA\Authenticator\Login', 'validate_email_authentication' ) ) {
1483 - return \WP2FA\Authenticator\Login::validate_email_authentication( $user );
1484 - }
1485 -
1486 - if ( class_exists( '\WP2FA\Authenticator\Authentication' ) && method_exists( '\WP2FA\Authenticator\Authentication', 'validate_token' ) && isset( $_REQUEST['authcode'] ) ) {
1487 - return \WP2FA\Authenticator\Authentication::validate_token( $user, sanitize_text_field( wp_unslash( $_REQUEST['authcode'] ) ) );
1488 - }
1489 -
1490 - return false;
1491 - }
1492 -
1493 - public function validate_wp2fa_backup_codes( $user ) {
1494 - if ( class_exists( '\WP2FA\Methods\Backup_Codes' ) && method_exists( '\WP2FA\Methods\Backup_Codes', 'validate_backup_codes' ) ) {
1495 - return \WP2FA\Methods\Backup_Codes::validate_backup_codes( $user );
1496 - }
1497 -
1498 - if ( class_exists( '\WP2FA\Authenticator\Backup_Codes' ) && method_exists( '\WP2FA\Authenticator\Backup_Codes', 'validate_backup_codes' ) ) {
1499 - return \WP2FA\Authenticator\Backup_Codes::validate_backup_codes( $user );
1500 - }
1501 -
1502 - return false;
1503 - }
1504 -
1505 1416 public function process_login_2fa() {
1506 - global $wp2fa;
1507 -
1508 1417 if ( ! isset( $_POST['uwp-auth-id'], $_POST['wp-auth-nonce'] ) ) {
1509 1418 return;
1510 1419 }
1511 1420
@@ -1510,64 +1419,46 @@
1510 1419 }
1511 1420
1512 1421 $auth_id = (int) $_POST['uwp-auth-id'];
1513 1422 $user = get_userdata( $auth_id );
1514 -
1515 1423 if ( ! $user ) {
1516 1424 $message = aui()->alert(
1517 - array(
1425 + array(
1518 1426 'type' => 'error',
1519 1427 'content' => __( 'Invalid user data. Please try again.', 'userswp' ),
1520 - )
1428 + )
1521 1429 );
1522 1430
1523 1431 wp_send_json_error( array( 'message' => $message ) );
1524 1432 }
1525 1433
1434 + global $wp2fa;
1435 +
1526 1436 $nonce = ( isset( $_POST['wp-auth-nonce'] ) ) ? sanitize_textarea_field( wp_unslash( $_POST['wp-auth-nonce'] ) ) : '';
1437 + if ( true !== \WP2FA\Authenticator\Login::verify_login_nonce( $user->ID, $nonce ) ) {
1527 1438
1528 - if ( true !== \WP2FA\Authenticator\Login::verify_login_nonce( $user->ID, $nonce ) ) {
1529 1439 $message = aui()->alert(
1530 - array(
1440 + array(
1531 1441 'type' => 'error',
1532 1442 'content' => __( 'Invalid request! Please try again.', 'userswp' ),
1533 - )
1443 + )
1534 1444 );
1535 1445
1536 1446 wp_send_json_error( array( 'message' => $message ) );
1537 1447 }
1538 1448
1539 - if ( isset( $_POST['provider'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing
1540 - $provider = sanitize_textarea_field( wp_unslash( $_POST['provider'] ) ); // phpcs:ignore WordPress.Security.NonceVerification.Missing
1541 - } else {
1542 - $provider = '';
1543 - }
1544 -
1545 - $error = '';
1546 -
1547 - try {
1548 - $is_enabled = \WP2FA\Admin\Controllers\Settings::is_provider_enabled_for_role( \WP2FA\Admin\Helpers\User_Helper::get_user_role( $user ), $provider );
1549 -
1550 - if ( ! $is_enabled ) {
1551 - $error = __( 'Invalid 2FA provider for user.', 'userswp' );
1449 + if ( isset( $_POST['provider'] ) ) {
1450 + $provider = sanitize_textarea_field( wp_unslash( $_POST['provider'] ) );
1451 + $providers = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1452 + if ( isset( $providers[ $provider ] ) ) {
1453 + $provider = $providers[ $provider ];
1454 + } elseif ( isset( $provider ) ) {
1455 + $provider = $provider;
1456 + } else {
1457 + $provider = $provider;
1552 1458 }
1553 - } catch ( \Exception $e ) {
1554 - $error = $e->getMessage();
1555 1459 }
1556 1460
1557 - if ( $error ) {
1558 - do_action( 'wp_login_failed', $user->user_login );
1559 -
1560 - $message = aui()->alert(
1561 - array(
1562 - 'type' => 'error',
1563 - 'content' => $error
1564 - )
1565 - );
1566 -
1567 - wp_send_json_error( array( 'message' => $message ) );
1568 - }
1569 -
1570 1461 // If this is an email login, or if the user failed validation previously, lets send the code to the user.
1571 1462 if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::pre_process_email_authentication( $user ) ) {
1572 1463
1573 1464 }
@@ -1572,16 +1463,17 @@
1572 1463
1573 1464 }
1574 1465
1575 1466 // Validate TOTP.
1576 - if ( 'totp' === $provider && true !== $this->validate_wp2fa_totp_authentication( $user ) ) {
1467 + if ( 'totp' === $provider && true !== \WP2FA\Authenticator\Login::validate_totp_authentication( $user ) ) {
1468 +
1577 1469 do_action( 'wp_login_failed', $user->user_login );
1578 1470
1579 1471 $message = aui()->alert(
1580 - array(
1472 + array(
1581 1473 'type' => 'error',
1582 1474 'content' => __( 'Invalid verification code.', 'userswp' ),
1583 - )
1475 + )
1584 1476 );
1585 1477
1586 1478 wp_send_json_error( array( 'message' => $message ) );
1587 1479 }
@@ -1586,26 +1478,27 @@
1586 1478 wp_send_json_error( array( 'message' => $message ) );
1587 1479 }
1588 1480
1589 1481 // Validate Email.
1590 - if ( 'email' === $provider && true !== $this->validate_wp2fa_email_authentication( $user ) ) {
1482 + if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::validate_email_authentication( $user ) ) {
1483 +
1591 1484 do_action( 'wp_login_failed', $user->user_login );
1592 1485
1593 1486 if ( isset( $_REQUEST['wp-2fa-email-code-resend'] ) && 1 == $_REQUEST['wp-2fa-email-code-resend'] ) {
1594 1487 $message = aui()->alert(
1595 - array(
1488 + array(
1596 1489 'type' => 'info',
1597 1490 'content' => __( 'A new code has been sent.', 'userswp' ),
1598 - )
1491 + )
1599 1492 );
1600 1493
1601 1494 wp_send_json_error( array( 'message' => $message ) );
1602 1495 } else {
1603 1496 $message = aui()->alert(
1604 - array(
1497 + array(
1605 1498 'type' => 'error',
1606 1499 'content' => __( 'Invalid verification code.', 'userswp' ),
1607 - )
1500 + )
1608 1501 );
1609 1502
1610 1503 wp_send_json_error( array( 'message' => $message ) );
1611 1504 }
@@ -1611,16 +1504,17 @@
1611 1504 }
1612 1505 }
1613 1506
1614 1507 // Backup Codes.
1615 - if ( 'backup_codes' === $provider && true !== $this->validate_wp2fa_backup_codes( $user ) ) {
1508 + if ( 'backup_codes' === $provider && true !== \WP2FA\Authenticator\Login::validate_backup_codes( $user ) ) {
1509 +
1616 1510 do_action( 'wp_login_failed', $user->user_login );
1617 1511
1618 1512 $message = aui()->alert(
1619 - array(
1513 + array(
1620 1514 'type' => 'error',
1621 1515 'content' => __( 'Invalid backup code.', 'userswp' ),
1622 - )
1516 + )
1623 1517 );
1624 1518
1625 1519 wp_send_json_error( array( 'message' => $message ) );
1626 1520 }
@@ -1628,9 +1522,8 @@
1628 1522 \WP2FA\Authenticator\Login::delete_login_nonce( $user->ID );
1629 1523
1630 1524 $rememberme = false;
1631 1525 $remember = ( isset( $_REQUEST['rememberme'] ) ) ? filter_var( $_REQUEST['rememberme'], FILTER_VALIDATE_BOOLEAN ) : '';
1632 -
1633 1526 if ( ! empty( $remember ) ) {
1634 1527 $rememberme = true;
1635 1528 }
1636 1529
@@ -1637,17 +1530,13 @@
1637 1530 wp_set_auth_cookie( $user->ID, $rememberme );
1638 1531
1639 1532 do_action( 'two_factor_user_authenticated', $user );
1640 1533
1641 - if ( defined( 'WP_2FA_PREFIX' ) ) {
1642 - do_action( WP_2FA_PREFIX . 'user_authenticated', $user );
1643 - }
1644 -
1645 1534 $message = aui()->alert(
1646 - array(
1535 + array(
1647 1536 'type' => 'success',
1648 1537 'content' => __( 'Validation successful. Redirecting...', 'userswp' ),
1649 - )
1538 + )
1650 1539 );
1651 1540
1652 1541 wp_send_json_success( array( 'message' => $message ) );
1653 1542 }
@@ -1744,12 +1633,9 @@
1744 1633 }
1745 1634
1746 1635 do_action( 'uwp_after_validate', $result, 'forgot', $data );
1747 1636
1748 - $login_or_email = trim( $data['email'] );
1749 - $user_data = is_email( $login_or_email )
1750 - ? get_user_by( 'email', $login_or_email )
1751 - : get_user_by( 'login', $login_or_email );
1637 + $user_data = get_user_by( 'email', $data['email'] );
1752 1638
1753 1639 // if no user we fake it and bail
1754 1640 if ( ! $user_data ) {
1755 1641 $args = apply_filters(
@@ -1755,9 +1641,9 @@
1755 1641 $args = apply_filters(
1756 1642 'uwp_forgot_error_message',
1757 1643 array(
1758 1644 'type' => 'error',
1759 - 'content' => __( 'Invalid username/email or user doesn\'t exist.', 'userswp' ),
1645 + 'content' => __( 'Invalid email or user doesn\'t exists.', 'userswp' ),
1760 1646 )
1761 1647 );
1762 1648
1763 1649 $message = aui()->alert( $args );
@@ -1772,21 +1658,12 @@
1772 1658
1773 1659 // make sure user account is active before account reset
1774 1660 $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true );
1775 1661 if ( $mod_value == 'email_unconfirmed' ) {
1776 - $resend_link = uwp_get_forgot_page_url();
1777 - $resend_link = add_query_arg(
1778 - array(
1779 - 'user_id' => $user_data->ID,
1780 - 'action' => 'uwp_resend',
1781 - '_nonce' => wp_create_nonce('uwp_resend'),
1782 - ),
1783 - $resend_link
1784 - );
1785 1662 $message = aui()->alert(
1786 1663 array(
1787 1664 'type' => 'error',
1788 - 'content' => sprintf(__('Your account is not activated yet. Please activate your account first. <a href="%s">Resend</a>.', 'userswp'), $resend_link),
1665 + 'content' => __( 'Your account is not activated yet. Please activate your account first.', 'userswp' ),
1789 1666 )
1790 1667 );
1791 1668 if ( wp_doing_ajax() ) {
1792 1669 wp_send_json_error( $message );
@@ -1791,8 +1668,9 @@
1791 1668 if ( wp_doing_ajax() ) {
1792 1669 wp_send_json_error( $message );
1793 1670 } else {
1794 1671 $uwp_notices[] = array( 'forgot' => $message );
1672 +
1795 1673 return;
1796 1674 }
1797 1675 }
1798 1676
@@ -1807,8 +1685,9 @@
1807 1685 }
1808 1686
1809 1687 $as_password = apply_filters( 'uwp_forgot_message_as_password', false );
1810 1688
1689 + global $wpdb, $wp_hasher;
1811 1690 $reset_link = '';
1812 1691
1813 1692 if ( $as_password ) {
1814 1693 $new_pass = wp_generate_password( 12, false );
@@ -1820,21 +1699,17 @@
1820 1699 $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
1821 1700 $message .= '<p>' . sprintf( __( 'Password: %s', 'userswp' ), $new_pass ) . '</p>';
1822 1701
1823 1702 } else {
1824 - // Use WordPress core to generate, hash (wp_fast_hash in WP 6.8+), and store the reset key.
1825 - // This ensures compatibility with check_password_reset_key() on all WP versions.
1826 - $key = get_password_reset_key( $user_data );
1703 + $key = wp_generate_password( 20, false );
1704 + do_action( 'retrieve_password_key', $user_data->user_login, $key );
1827 1705
1828 - if ( is_wp_error( $key ) ) {
1829 - if ( wp_doing_ajax() ) {
1830 - wp_send_json_error( $key->get_error_message() );
1831 - } else {
1832 - $uwp_notices[] = array( 'forgot' => aui()->alert( array( 'type' => 'error', 'content' => $key->get_error_message() ) ) );
1833 - return;
1834 - }
1706 + if ( empty( $wp_hasher ) ) {
1707 + require_once ABSPATH . 'wp-includes/class-phpass.php';
1708 + $wp_hasher = new PasswordHash( 8, true );
1835 1709 }
1836 -
1710 + $hashed = $wp_hasher->HashPassword( $key );
1711 + $wpdb->update( $wpdb->users, array( 'user_activation_key' => time() . ':' . $hashed ), array( 'user_login' => $user_data->user_login ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1837 1712 $message = '<p>' . __( 'You have requested to reset your password for the following account:', 'userswp' ) . '</p>';
1838 1713 $message .= home_url( '/' ) . '</p>';
1839 1714 $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
1840 1715 $message .= '<p>' . __( 'If this was by mistake, just ignore this email and nothing will happen.', 'userswp' ) . '</p>';
@@ -2127,21 +2002,8 @@
2127 2002 unset( $uploads_result[ $upload_file_key ] );
2128 2003 }
2129 2004 }
2130 2005
2131 - global $wpdb;
2132 - $file_field_names = $wpdb->get_col(
2133 - $wpdb->prepare(
2134 - "SELECT htmlvar_name FROM " . uwp_get_table_prefix() . "uwp_form_fields WHERE form_type = %s AND field_type IN ('file','image')",
2135 - 'account'
2136 - )
2137 - );
2138 - foreach ( $file_field_names as $file_field_name ) {
2139 - if ( isset( $result[ $file_field_name ] ) && ! isset( $uploads_result[ $file_field_name ] ) ) {
2140 - unset( $result[ $file_field_name ] );
2141 - }
2142 - }
2143 -
2144 2006 $result = array_merge( $result, $uploads_result );
2145 2007
2146 2008 $args = array(
2147 2009 'ID' => get_current_user_id(),
@@ -2371,94 +2233,46 @@
2371 2233 * @package userswp
2372 2234 * @since 1.0.0
2373 2235 */
2374 2236 public function upload_file_remove() {
2375 - global $wpdb;
2376 -
2377 2237 check_ajax_referer( 'uwp_basic_nonce', 'security' );
2378 2238
2379 - // Check user logged in.
2380 - if ( ! is_user_logged_in() ) {
2381 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Access denied!', 'userswp' ) ) );
2382 - wp_send_json_error( array( 'message' => $message ) );
2383 - }
2384 -
2239 + $htmlvar = esc_sql( strip_tags( $_POST['htmlvar'] ) );
2385 2240 $user_id = ! empty( $_POST['uid'] ) ? absint( $_POST['uid'] ) : 0;
2386 - $htmlvar = ! empty( $_POST['htmlvar'] ) ? sanitize_key( $_POST['htmlvar'] ) : '';
2387 2241
2388 - if ( empty( $user_id ) || empty( $htmlvar ) ) {
2389 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid data!', 'userswp' ) ) );
2390 - wp_send_json_error( array( 'message' => $message ) );
2242 + if ( empty( $user_id ) ) {
2243 + wp_die( -1 );
2391 2244 }
2392 2245
2393 - // Validate the user / admin.
2394 - if ( ! ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) {
2395 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid access!', 'userswp' ) ) );
2396 - wp_send_json_error( array( 'message' => $message ) );
2246 + if ( ! ( is_user_logged_in() && ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) ) {
2247 + wp_send_json_error( __( 'Invalid access!', 'userswp' ) );
2397 2248 }
2398 2249
2250 + // Remove file
2399 2251 if ( $htmlvar == 'banner_thumb' ) {
2400 - $field_key = 'banner';
2252 + $file = uwp_get_usermeta( $user_id, 'banner_thumb' );
2401 2253 $type = 'banner';
2402 - } else if ( $htmlvar == 'avatar_thumb' ) {
2403 - $field_key = 'avatar';
2254 + } elseif ( $htmlvar == 'avatar_thumb' ) {
2255 + $file = uwp_get_usermeta( $user_id, 'avatar_thumb' );
2404 2256 $type = 'avatar';
2405 2257 } else {
2406 - $field_key = $htmlvar;
2258 + $file = '';
2407 2259 $type = '';
2408 2260 }
2409 2261
2410 - $field = $wpdb->get_row( $wpdb->prepare( "SELECT * FROM " . uwp_get_table_prefix() . "uwp_form_fields WHERE htmlvar_name = %s LIMIT 1", $field_key ) );
2411 -
2412 - // Check field exists.
2413 - if ( empty( $field ) ) {
2414 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field!', 'userswp' ) ) );
2415 - wp_send_json_error( array( 'message' => $message ) );
2416 - }
2417 -
2418 - // Validate field access.
2419 - if ( ! empty( $field->for_admin_use ) && ! current_user_can( 'manage_options' ) ) {
2420 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'You are not allowed to perform this action!', 'userswp' ) ) );
2421 - wp_send_json_error( array( 'message' => $message ) );
2422 - }
2423 -
2424 - if ( ! in_array( $field->field_type, array( 'file', 'image' ) ) ) {
2425 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field type!', 'userswp' ) ) );
2426 - wp_send_json_error( array( 'message' => $message ) );
2427 - }
2428 -
2429 - $value = uwp_get_usermeta( $user_id, $htmlvar );
2430 -
2431 2262 uwp_update_usermeta( $user_id, $htmlvar, '' );
2432 2263
2433 - if ( $value && validate_file( $value ) === 0 ) {
2264 + if ( $file ) {
2434 2265 $uploads = wp_upload_dir();
2435 2266 $upload_path = $uploads['basedir'];
2267 + $unlink_file = untrailingslashit( $upload_path ) . '/' . ltrim( $file, '/' );
2436 2268
2437 - if ( strpos( $value, 'http://' ) === 0 || strpos( $value, 'https://' ) === 0 ) {
2438 - // Get the relative url.
2439 - $value = uwp_get_file_relative_url( $value );
2440 - }
2269 + if ( is_file( $unlink_file ) && file_exists( $unlink_file ) ) {
2270 + @unlink( $unlink_file );
2271 + $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_file );
2441 2272
2442 - $unlink_file = untrailingslashit( $upload_path ) . '/' . trim( $value, '/\\' );
2443 -
2444 - // Canonicalize and enforce containment inside the uploads directory before deleting.
2445 - $real_upload_path = realpath( $upload_path );
2446 - $real_unlink_file = realpath( $unlink_file );
2447 -
2448 - if ( $real_upload_path && $real_unlink_file && is_file( $real_unlink_file )
2449 - && strpos( $real_unlink_file, $real_upload_path . DIRECTORY_SEPARATOR ) === 0 ) {
2450 - wp_delete_file( $real_unlink_file );
2451 -
2452 - // For avatar/banner, also remove the original (non-thumb) file.
2453 - if ( $type ) {
2454 - $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $real_unlink_file );
2455 - $real_unlink_ori_file = realpath( $unlink_ori_file );
2456 -
2457 - if ( $real_unlink_ori_file && is_file( $real_unlink_ori_file )
2458 - && strpos( $real_unlink_ori_file, $real_upload_path . DIRECTORY_SEPARATOR ) === 0 ) {
2459 - wp_delete_file( $real_unlink_ori_file );
2460 - }
2273 + if ( is_file( $unlink_ori_file ) && file_exists( $unlink_ori_file ) ) {
2274 + @unlink( $unlink_ori_file );
2461 2275 }
2462 2276 }
2463 2277 }
2464 2278
@@ -2704,9 +2518,9 @@
2704 2518 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2705 2519 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2706 2520 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2707 2521 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2708 - 'input_group_right' => '<div class="input-group-text px-2 bg-transparent border-0x" onclick="jQuery(this).parent().parent().find(\'input\').val(\'\');"><i class="fas fa-times uwp-search-input-label-clear text-muted c-pointer" title="' . esc_attr__( 'Clear field', 'userswp' ) . '" ></i></div>',
2522 + 'input_group_right' => '<div class="input-group-text px-2 bg-transparent border-0x" onclick="jQuery(this).parent().parent().find(\'input\').val(\'\');"><i class="fas fa-times uwp-search-input-label-clear text-muted c-pointer" title="' . esc_attr__( 'Clear field', 'uwp-search' ) . '" ></i></div>',
2709 2523 )
2710 2524 );
2711 2525 } else {
2712 2526 ?>
@@ -3940,26 +3754,17 @@
3940 3754 $site_title = uwp_get_form_label( $field );
3941 3755 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3942 3756 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3943 3757
3944 - $is_forgot_email = ( $form_type === 'forgot' && $field->htmlvar_name === 'email' );
3945 - $input_type = $is_forgot_email ? 'text' : 'email';
3946 - if ( $is_forgot_email ) {
3947 - $site_title = __( 'Username or Email', 'userswp' );
3948 - $placeholder = $site_title . ( ! empty( $field->is_required ) ? ' *' : '' );
3949 - } else {
3950 - $placeholder = uwp_get_field_placeholder( $field );
3951 - }
3952 -
3953 3758 if ( $design_style ) {
3954 3759 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3955 3760
3956 3761 echo aui()->input(
3957 3762 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3958 - 'type' => $input_type,
3763 + 'type' => 'email',
3959 3764 'id' => esc_attr( $field->htmlvar_name ),
3960 3765 'name' => esc_attr( $field->htmlvar_name ),
3961 - 'placeholder' => esc_attr( $placeholder ),
3766 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3962 3767 'title' => esc_html( $site_title ),
3963 3768 'value' => esc_attr( wp_unslash( $value ) ),
3964 3769 'required' => (bool) $field->is_required,
3965 3770 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
@@ -3995,9 +3800,9 @@
3995 3800
3996 3801 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3997 3802 class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3998 3803 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3999 - placeholder="<?php echo esc_attr( $placeholder ); ?>"
3804 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4000 3805 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
4001 3806 title="<?php echo esc_attr( $site_title ); ?>"
4002 3807 <?php
4003 3808 if ( $field->is_required == 1 ) {
@@ -4003,9 +3808,9 @@
4003 3808 if ( $field->is_required == 1 ) {
4004 3809 echo 'required="required"';
4005 3810 }
4006 3811 ?>
4007 - type="<?php echo esc_attr( $input_type ); ?>"
3812 + type="email"
4008 3813 />
4009 3814 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4010 3815 <?php if ( $field->is_required ) { ?>
4011 3816 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
@@ -4501,9 +4306,9 @@
4501 4306 // If no html then we run the standard output.
4502 4307 if ( empty( $html ) ) {
4503 4308
4504 4309 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4505 - $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds margin so we remove ours
4310 + $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds marginso we remove ours
4506 4311 $bs_sr_only = $design_style ? 'sr-only' : '';
4507 4312 $bs_form_control = $design_style ? 'form-control' : '';
4508 4313
4509 4314 ob_start(); // Start buffering;
@@ -5066,13 +4871,13 @@
5066 4871 function (event) {
5067 4872 var $form = $(this).closest('form');
5068 4873 if( ! $form.hasClass('uwp-login-form') ) {
5069 4874 uwp_checkPasswordStrength(
5070 - $form.find('input[name=password]'),
5071 - $form.find('input[name=confirm_password]'),
5072 - $form.find('#uwp-password-strength'),
5073 - $form.find('button[type="submit"], input[type="submit"]'),
5074 - ['black', 'listed', 'word']
4875 + $('input[name=password]', $form), // First password field
4876 + $('input[name=confirm_password]', $form), // Second password field
4877 + $('#uwp-password-strength', $form), // Strength meter
4878 + $('input[type=submit]', $form), // Submit button
4879 + ['black', 'listed', 'word'] // Blacklisted words
5075 4880 );
5076 4881 }
5077 4882 }
5078 4883 );
@@ -5099,15 +4904,12 @@
5099 4904 public function ajax_forgot_password_form() {
5100 4905
5101 4906 // add the modal error container
5102 4907 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
5103 - $args = array(
5104 - 'form_title' => '',
5105 - 'css_class' => ''
5106 - );
4908 +
5107 4909 // get the form
5108 4910 ob_start();
5109 - uwp_get_template( 'bootstrap/forgot.php', $args );
4911 + uwp_get_template( 'bootstrap/forgot.php' );
5110 4912 $form = ob_get_clean();
5111 4913
5112 4914 // bs5
5113 4915 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {