PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.47
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.47
1.2.74 1.2.73 1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.20 1.0.21 All 174 releases
← All changes | includes/class-forms.php +67 -125 1.2.631.2.47 View file →
@@ -102,26 +102,27 @@
102 102 $processed = true;
103 103 }
104 104
105 105 if ( $processed ) {
106 +
106 107 if ( is_wp_error( $errors ) ) {
107 - aui()->alert(
108 - array(
109 - 'type' => 'error',
110 - 'content' => wp_kses_post( $errors->get_error_message() )
111 - ),
112 - true
113 - );
114 - } else if ( $redirect ) {
108 + echo aui()->alert(
109 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
110 + 'type' => 'error',
111 + 'class' => 'text-center',
112 + 'content' => wp_kses_post( $errors->get_error_message() ),
113 + )
114 + );
115 + } elseif ( $redirect ) {
115 116 wp_safe_redirect( $redirect );
116 117 exit();
117 - } else {
118 - aui()->alert(
119 - array(
120 - 'type' => 'success',
121 - 'content' => wp_kses_post( $message )
122 - ),
123 - true
118 + } else {
119 + echo aui()->alert(
120 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
121 + 'type' => 'success',
122 + 'class' => 'text-center',
123 + 'content' => wp_kses_post( $message ),
124 + )
124 125 );
125 126 }
126 127 }
127 128
@@ -195,9 +196,8 @@
195 196 * @since 1.0.0
196 197 */
197 198 public function process_image_crop( $data = array(), $type = 'avatar', $unlink_prev_img = false ) {
198 199 global $wpdb;
199 -
200 200 if ( ! is_user_logged_in() ) {
201 201 return false;
202 202 }
203 203
@@ -204,29 +204,8 @@
204 204 if ( empty( $_POST['uwp_crop_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_crop_nonce'], 'uwp_crop_nonce_' . $type ) ) {
205 205 return;
206 206 }
207 207
208 - $image_url = ! empty( $data['uwp_crop'] ) ? esc_url( $data['uwp_crop'] ) : '';
209 -
210 - if ( empty( $image_url ) ) {
211 - return new WP_Error( 'empty_image', __( 'Upload valid image.', 'userswp' ) );
212 - }
213 -
214 - // Ensure we have a valid URL with an allowed meme type.
215 - $image_url = $this->normalize_url( $image_url );
216 -
217 - $content_url = str_replace( array( 'https://', 'http://' ) , '', untrailingslashit( WP_CONTENT_URL ) );
218 - $_image_url = str_replace( array( 'https://', 'http://' ), '', $image_url );
219 - if ( strpos( $_image_url, $content_url ) !== 0 ) {
220 - return new WP_Error( 'invalid_image', __( 'Invalid image url.', 'userswp' ) );
221 - }
222 -
223 - $filetype = wp_check_filetype( $image_url );
224 -
225 - if ( empty( $filetype['ext'] ) ) {
226 - return new WP_Error( 'invalid_image', __( 'Invalid image type.', 'userswp' ) );
227 - }
228 -
229 208 // If is current user's profile (profile.php)
230 209 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
231 210 $user_id = get_current_user_id();
232 211 // If is another user's profile page
@@ -236,8 +215,21 @@
236 215 } else {
237 216 $user_id = get_current_user_id();
238 217 }
239 218
219 + // Ensure we have a valid URL with an allowed meme type.
220 + $image_url = $this->normalize_url( esc_url( $data['uwp_crop'] ) );
221 + $filetype = wp_check_filetype( $image_url );
222 +
223 + $errors = new WP_Error();
224 + if ( empty( $image_url ) || empty( $filetype['ext'] ) ) {
225 + $errors->add( 'something_wrong', __( 'Something went wrong. Please contact site admin.', 'userswp' ) );
226 + }
227 +
228 + if ( $errors->has_errors() ) {
229 + return $errors;
230 + }
231 +
240 232 // Retrieve current thumbnail.
241 233 $current_field = 'avatar' === $type ? 'avatar_thumb' : 'banner_thumb';
242 234 $current_thumbnail = $this->normalize_url( uwp_get_usermeta( $user_id, $current_field, '' ) );
243 235 $thumb_postfix = '_uwp_' . $type . '_thumb';
@@ -260,14 +252,13 @@
260 252 $ext = $filetype['ext']; // to get extension
261 253 $name = sanitize_file_name( pathinfo( $image_path, PATHINFO_FILENAME ) ); //file name without extension
262 254 $thumb_image_name = $name . $thumb_postfix . '.' . $ext;
263 255 $thumb_image_location = str_replace( $name . '.' . $ext, $thumb_image_name, $image_path );
264 -
265 256 //Get the new coordinates to crop the image.
266 - $x = $data['uwpx'];
267 - $y = $data['uwpy'];
268 - $w = $data['uwpw'];
269 - $h = $data['uwph'];
257 + $x = $data['x'];
258 + $y = $data['y'];
259 + $w = $data['w'];
260 + $h = $data['h'];
270 261 //Scale the image based on cropped width setting
271 262 $scale = $full_width / $w;
272 263 //$scale = 1; // no scaling
273 264
@@ -327,11 +318,8 @@
327 318 *
328 319 */
329 320 public function normalize_url( $url ) {
330 321
331 - if ( empty( $url ) ) {
332 - return '';
333 - }
334 322 // Normalize.
335 323 $url = wp_normalize_path( $url );
336 324
337 325 // Remove query vars.
@@ -479,10 +467,10 @@
479 467 }
480 468 } elseif ( ! empty( $notice ) ) {
481 469 echo wp_kses_post( $notice );
482 470 }
483 - }
484 - }
471 +}
472 +}
485 473
486 474 if ( $type == 'change' ) {
487 475 $user_id = get_current_user_id();
488 476 $password_nag = get_user_option( 'default_password_nag', $user_id );
@@ -535,15 +523,9 @@
535 523 if ( isset( $data['uwp_register_hp'] ) && '' != $data['uwp_register_hp'] ) {
536 524 wp_die( esc_html__( 'No spam please!', 'userswp' ) );
537 525 }
538 526
539 - $form_id = 1;
540 -
541 - if ( ! empty( $data['uwp_register_form_id'] ) ) {
542 - $form_id = (int) $data['uwp_register_form_id'];
543 - }
544 -
545 - if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce-' . $form_id ) ) {
527 + if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce' ) ) {
546 528 $message = aui()->alert(
547 529 array(
548 530 'type' => 'error',
549 531 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
@@ -715,8 +697,14 @@
715 697 'last_name' => esc_attr( $last_name ),
716 698 'user_url' => esc_url_raw( $user_url ),
717 699 );
718 700
701 + $form_id = 1;
702 +
703 + if ( ! empty( $data['uwp_register_form_id'] ) ) {
704 + $form_id = (int) $data['uwp_register_form_id'];
705 + }
706 +
719 707 // Set user role by form.
720 708 $user_role = uwp_get_register_form_by( $form_id, 'user_role' );
721 709
722 710 if ( ! empty( $user_role ) ) {
@@ -1674,21 +1662,12 @@
1674 1662
1675 1663 // make sure user account is active before account reset
1676 1664 $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true );
1677 1665 if ( $mod_value == 'email_unconfirmed' ) {
1678 - $resend_link = uwp_get_forgot_page_url();
1679 - $resend_link = add_query_arg(
1680 - array(
1681 - 'user_id' => $user_data->ID,
1682 - 'action' => 'uwp_resend',
1683 - '_nonce' => wp_create_nonce('uwp_resend'),
1684 - ),
1685 - $resend_link
1686 - );
1687 1666 $message = aui()->alert(
1688 1667 array(
1689 1668 'type' => 'error',
1690 - 'content' => sprintf(__('Your account is not activated yet. Please activate your account first. <a href="%s">Resend</a>.', 'userswp'), $resend_link),
1669 + 'content' => __( 'Your account is not activated yet. Please activate your account first.', 'userswp' ),
1691 1670 )
1692 1671 );
1693 1672 if ( wp_doing_ajax() ) {
1694 1673 wp_send_json_error( $message );
@@ -1693,8 +1672,9 @@
1693 1672 if ( wp_doing_ajax() ) {
1694 1673 wp_send_json_error( $message );
1695 1674 } else {
1696 1675 $uwp_notices[] = array( 'forgot' => $message );
1676 +
1697 1677 return;
1698 1678 }
1699 1679 }
1700 1680
@@ -2257,81 +2237,46 @@
2257 2237 * @package userswp
2258 2238 * @since 1.0.0
2259 2239 */
2260 2240 public function upload_file_remove() {
2261 - global $wpdb;
2262 -
2263 2241 check_ajax_referer( 'uwp_basic_nonce', 'security' );
2264 2242
2265 - // Check user logged in.
2266 - if ( ! is_user_logged_in() ) {
2267 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Access denied!', 'userswp' ) ) );
2268 - wp_send_json_error( array( 'message' => $message ) );
2269 - }
2270 -
2243 + $htmlvar = esc_sql( strip_tags( $_POST['htmlvar'] ) );
2271 2244 $user_id = ! empty( $_POST['uid'] ) ? absint( $_POST['uid'] ) : 0;
2272 - $htmlvar = ! empty( $_POST['htmlvar'] ) ? sanitize_key( $_POST['htmlvar'] ) : '';
2273 2245
2274 - if ( empty( $user_id ) || empty( $htmlvar ) ) {
2275 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid data!', 'userswp' ) ) );
2276 - wp_send_json_error( array( 'message' => $message ) );
2246 + if ( empty( $user_id ) ) {
2247 + wp_die( -1 );
2277 2248 }
2278 2249
2279 - // Validate the user / admin.
2280 - if ( ! ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) {
2281 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid access!', 'userswp' ) ) );
2282 - wp_send_json_error( array( 'message' => $message ) );
2250 + if ( ! ( is_user_logged_in() && ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) ) {
2251 + wp_send_json_error( __( 'Invalid access!', 'userswp' ) );
2283 2252 }
2284 2253
2254 + // Remove file
2285 2255 if ( $htmlvar == 'banner_thumb' ) {
2286 - $field_key = 'banner';
2256 + $file = uwp_get_usermeta( $user_id, 'banner_thumb' );
2287 2257 $type = 'banner';
2288 - } else if ( $htmlvar == 'avatar_thumb' ) {
2289 - $field_key = 'avatar';
2258 + } elseif ( $htmlvar == 'avatar_thumb' ) {
2259 + $file = uwp_get_usermeta( $user_id, 'avatar_thumb' );
2290 2260 $type = 'avatar';
2291 2261 } else {
2292 - $field_key = $htmlvar;
2262 + $file = '';
2293 2263 $type = '';
2294 2264 }
2295 2265
2296 - $field = $wpdb->get_row( $wpdb->prepare( "SELECT * FROM " . uwp_get_table_prefix() . "uwp_form_fields WHERE htmlvar_name = %s LIMIT 1", $field_key ) );
2297 -
2298 - // Check field exists.
2299 - if ( empty( $field ) ) {
2300 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field!', 'userswp' ) ) );
2301 - wp_send_json_error( array( 'message' => $message ) );
2302 - }
2303 -
2304 - // Validate field access.
2305 - if ( ! empty( $field->for_admin_use ) && ! current_user_can( 'manage_options' ) ) {
2306 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'You are not allowed to perform this action!', 'userswp' ) ) );
2307 - wp_send_json_error( array( 'message' => $message ) );
2308 - }
2309 -
2310 - if ( ! in_array( $field->field_type, array( 'file', 'image' ) ) ) {
2311 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field type!', 'userswp' ) ) );
2312 - wp_send_json_error( array( 'message' => $message ) );
2313 - }
2314 -
2315 - $value = uwp_get_usermeta( $user_id, $htmlvar );
2316 -
2317 2266 uwp_update_usermeta( $user_id, $htmlvar, '' );
2318 2267
2319 - if ( $value ) {
2268 + if ( $file ) {
2320 2269 $uploads = wp_upload_dir();
2321 2270 $upload_path = $uploads['basedir'];
2322 - $unlink_file = untrailingslashit( $upload_path ) . '/' . ltrim( $value, '/' );
2271 + $unlink_file = untrailingslashit( $upload_path ) . '/' . ltrim( $file, '/' );
2323 2272
2324 2273 if ( is_file( $unlink_file ) && file_exists( $unlink_file ) ) {
2325 2274 @unlink( $unlink_file );
2275 + $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_file );
2326 2276
2327 - // For avatar/banner, also remove the original (non-thumb) file.
2328 - if ( $type ) {
2329 - $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_file );
2330 -
2331 - if ( is_file( $unlink_ori_file ) && file_exists( $unlink_ori_file ) ) {
2332 - @unlink( $unlink_ori_file );
2333 - }
2277 + if ( is_file( $unlink_ori_file ) && file_exists( $unlink_ori_file ) ) {
2278 + @unlink( $unlink_ori_file );
2334 2279 }
2335 2280 }
2336 2281 }
2337 2282
@@ -4365,9 +4310,9 @@
4365 4310 // If no html then we run the standard output.
4366 4311 if ( empty( $html ) ) {
4367 4312
4368 4313 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4369 - $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds margin so we remove ours
4314 + $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds marginso we remove ours
4370 4315 $bs_sr_only = $design_style ? 'sr-only' : '';
4371 4316 $bs_form_control = $design_style ? 'form-control' : '';
4372 4317
4373 4318 ob_start(); // Start buffering;
@@ -4930,13 +4875,13 @@
4930 4875 function (event) {
4931 4876 var $form = $(this).closest('form');
4932 4877 if( ! $form.hasClass('uwp-login-form') ) {
4933 4878 uwp_checkPasswordStrength(
4934 - $form.find('input[name=password]'),
4935 - $form.find('input[name=confirm_password]'),
4936 - $form.find('#uwp-password-strength'),
4937 - $form.find('button[type="submit"], input[type="submit"]'),
4938 - ['black', 'listed', 'word']
4879 + $('input[name=password]', $form), // First password field
4880 + $('input[name=confirm_password]', $form), // Second password field
4881 + $('#uwp-password-strength', $form), // Strength meter
4882 + $('input[type=submit]', $form), // Submit button
4883 + ['black', 'listed', 'word'] // Blacklisted words
4939 4884 );
4940 4885 }
4941 4886 }
4942 4887 );
@@ -4963,15 +4908,12 @@
4963 4908 public function ajax_forgot_password_form() {
4964 4909
4965 4910 // add the modal error container
4966 4911 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
4967 - $args = array(
4968 - 'form_title' => '',
4969 - 'css_class' => ''
4970 - );
4912 +
4971 4913 // get the form
4972 4914 ob_start();
4973 - uwp_get_template( 'bootstrap/forgot.php', $args );
4915 + uwp_get_template( 'bootstrap/forgot.php' );
4974 4916 $form = ob_get_clean();
4975 4917
4976 4918 // bs5
4977 4919 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {