PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.48
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.48
1.2.73 1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.20 1.0.21 1.0.22 All 173 releases
← All changes | includes/class-forms.php +74 -136 1.2.661.2.48 View file →
@@ -102,26 +102,27 @@
102 102 $processed = true;
103 103 }
104 104
105 105 if ( $processed ) {
106 +
106 107 if ( is_wp_error( $errors ) ) {
107 - aui()->alert(
108 - array(
109 - 'type' => 'error',
110 - 'content' => wp_kses_post( $errors->get_error_message() )
111 - ),
112 - true
113 - );
114 - } else if ( $redirect ) {
108 + echo aui()->alert(
109 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
110 + 'type' => 'error',
111 + 'class' => 'text-center',
112 + 'content' => wp_kses_post( $errors->get_error_message() ),
113 + )
114 + );
115 + } elseif ( $redirect ) {
115 116 wp_safe_redirect( $redirect );
116 117 exit();
117 - } else {
118 - aui()->alert(
119 - array(
120 - 'type' => 'success',
121 - 'content' => wp_kses_post( $message )
122 - ),
123 - true
118 + } else {
119 + echo aui()->alert(
120 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
121 + 'type' => 'success',
122 + 'class' => 'text-center',
123 + 'content' => wp_kses_post( $message ),
124 + )
124 125 );
125 126 }
126 127 }
127 128
@@ -195,9 +196,8 @@
195 196 * @since 1.0.0
196 197 */
197 198 public function process_image_crop( $data = array(), $type = 'avatar', $unlink_prev_img = false ) {
198 199 global $wpdb;
199 -
200 200 if ( ! is_user_logged_in() ) {
201 201 return false;
202 202 }
203 203
@@ -204,29 +204,8 @@
204 204 if ( empty( $_POST['uwp_crop_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_crop_nonce'], 'uwp_crop_nonce_' . $type ) ) {
205 205 return;
206 206 }
207 207
208 - $image_url = ! empty( $data['uwp_crop'] ) ? esc_url( $data['uwp_crop'] ) : '';
209 -
210 - if ( empty( $image_url ) ) {
211 - return new WP_Error( 'empty_image', __( 'Upload valid image.', 'userswp' ) );
212 - }
213 -
214 - // Ensure we have a valid URL with an allowed meme type.
215 - $image_url = $this->normalize_url( $image_url );
216 -
217 - $content_url = str_replace( array( 'https://', 'http://' ) , '', untrailingslashit( WP_CONTENT_URL ) );
218 - $_image_url = str_replace( array( 'https://', 'http://' ), '', $image_url );
219 - if ( strpos( $_image_url, $content_url ) !== 0 ) {
220 - return new WP_Error( 'invalid_image', __( 'Invalid image url.', 'userswp' ) );
221 - }
222 -
223 - $filetype = wp_check_filetype( $image_url );
224 -
225 - if ( empty( $filetype['ext'] ) ) {
226 - return new WP_Error( 'invalid_image', __( 'Invalid image type.', 'userswp' ) );
227 - }
228 -
229 208 // If is current user's profile (profile.php)
230 209 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
231 210 $user_id = get_current_user_id();
232 211 // If is another user's profile page
@@ -236,8 +215,21 @@
236 215 } else {
237 216 $user_id = get_current_user_id();
238 217 }
239 218
219 + // Ensure we have a valid URL with an allowed meme type.
220 + $image_url = $this->normalize_url( esc_url( $data['uwp_crop'] ) );
221 + $filetype = wp_check_filetype( $image_url );
222 +
223 + $errors = new WP_Error();
224 + if ( empty( $image_url ) || empty( $filetype['ext'] ) ) {
225 + $errors->add( 'something_wrong', __( 'Something went wrong. Please contact site admin.', 'userswp' ) );
226 + }
227 +
228 + if ( $errors->has_errors() ) {
229 + return $errors;
230 + }
231 +
240 232 // Retrieve current thumbnail.
241 233 $current_field = 'avatar' === $type ? 'avatar_thumb' : 'banner_thumb';
242 234 $current_thumbnail = $this->normalize_url( uwp_get_usermeta( $user_id, $current_field, '' ) );
243 235 $thumb_postfix = '_uwp_' . $type . '_thumb';
@@ -260,14 +252,13 @@
260 252 $ext = $filetype['ext']; // to get extension
261 253 $name = sanitize_file_name( pathinfo( $image_path, PATHINFO_FILENAME ) ); //file name without extension
262 254 $thumb_image_name = $name . $thumb_postfix . '.' . $ext;
263 255 $thumb_image_location = str_replace( $name . '.' . $ext, $thumb_image_name, $image_path );
264 -
265 256 //Get the new coordinates to crop the image.
266 - $x = $data['uwpx'];
267 - $y = $data['uwpy'];
268 - $w = $data['uwpw'];
269 - $h = $data['uwph'];
257 + $x = $data['x'];
258 + $y = $data['y'];
259 + $w = $data['w'];
260 + $h = $data['h'];
270 261 //Scale the image based on cropped width setting
271 262 $scale = $full_width / $w;
272 263 //$scale = 1; // no scaling
273 264
@@ -327,11 +318,8 @@
327 318 *
328 319 */
329 320 public function normalize_url( $url ) {
330 321
331 - if ( empty( $url ) ) {
332 - return '';
333 - }
334 322 // Normalize.
335 323 $url = wp_normalize_path( $url );
336 324
337 325 // Remove query vars.
@@ -360,20 +348,22 @@
360 348 if ( ! is_user_logged_in() ) {
361 349 return false;
362 350 }
363 351
352 + if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type ) ) {
353 + return;
354 + }
355 +
364 356 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
365 357 $user_id = get_current_user_id();
366 - } elseif ( is_admin() && current_user_can( 'manage_options' ) && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
358 + // If is another user's profile page
359 + } elseif ( is_admin() && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
367 360 $user_id = absint( $_GET['user_id'] );
361 + // Otherwise something is wrong.
368 362 } else {
369 363 $user_id = get_current_user_id();
370 364 }
371 365
372 - if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type . '_' . $user_id ) ) {
373 - return;
374 - }
375 -
376 366 $errors = new WP_Error();
377 367 if ( empty( $user_id ) ) {
378 368 $errors->add( 'something_wrong', __( 'Something went wrong. Please try again.', 'userswp' ) );
379 369 }
@@ -533,15 +523,9 @@
533 523 if ( isset( $data['uwp_register_hp'] ) && '' != $data['uwp_register_hp'] ) {
534 524 wp_die( esc_html__( 'No spam please!', 'userswp' ) );
535 525 }
536 526
537 - $form_id = 1;
538 -
539 - if ( ! empty( $data['uwp_register_form_id'] ) ) {
540 - $form_id = (int) $data['uwp_register_form_id'];
541 - }
542 -
543 - if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce-' . $form_id ) ) {
527 + if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce' ) ) {
544 528 $message = aui()->alert(
545 529 array(
546 530 'type' => 'error',
547 531 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
@@ -713,8 +697,14 @@
713 697 'last_name' => esc_attr( $last_name ),
714 698 'user_url' => esc_url_raw( $user_url ),
715 699 );
716 700
701 + $form_id = 1;
702 +
703 + if ( ! empty( $data['uwp_register_form_id'] ) ) {
704 + $form_id = (int) $data['uwp_register_form_id'];
705 + }
706 +
717 707 // Set user role by form.
718 708 $user_role = uwp_get_register_form_by( $form_id, 'user_role' );
719 709
720 710 if ( ! empty( $user_role ) ) {
@@ -1672,21 +1662,12 @@
1672 1662
1673 1663 // make sure user account is active before account reset
1674 1664 $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true );
1675 1665 if ( $mod_value == 'email_unconfirmed' ) {
1676 - $resend_link = uwp_get_forgot_page_url();
1677 - $resend_link = add_query_arg(
1678 - array(
1679 - 'user_id' => $user_data->ID,
1680 - 'action' => 'uwp_resend',
1681 - '_nonce' => wp_create_nonce('uwp_resend'),
1682 - ),
1683 - $resend_link
1684 - );
1685 1666 $message = aui()->alert(
1686 1667 array(
1687 1668 'type' => 'error',
1688 - 'content' => sprintf(__('Your account is not activated yet. Please activate your account first. <a href="%s">Resend</a>.', 'userswp'), $resend_link),
1669 + 'content' => __( 'Your account is not activated yet. Please activate your account first.', 'userswp' ),
1689 1670 )
1690 1671 );
1691 1672 if ( wp_doing_ajax() ) {
1692 1673 wp_send_json_error( $message );
@@ -1691,8 +1672,9 @@
1691 1672 if ( wp_doing_ajax() ) {
1692 1673 wp_send_json_error( $message );
1693 1674 } else {
1694 1675 $uwp_notices[] = array( 'forgot' => $message );
1676 +
1695 1677 return;
1696 1678 }
1697 1679 }
1698 1680
@@ -1985,9 +1967,9 @@
1985 1967 $file_obj = new UsersWP_Files();
1986 1968
1987 1969 do_action( 'uwp_before_validate', 'account' );
1988 1970
1989 - $result = uwp_validate_fields( $data, 'account', false, "AND `field_type` != 'file'" );
1971 + $result = uwp_validate_fields( $data, 'account' );
1990 1972
1991 1973 $result = apply_filters( 'uwp_validate_result', $result, 'account', $data );
1992 1974
1993 1975 if ( is_wp_error( $result ) ) {
@@ -2255,87 +2237,46 @@
2255 2237 * @package userswp
2256 2238 * @since 1.0.0
2257 2239 */
2258 2240 public function upload_file_remove() {
2259 - global $wpdb;
2260 -
2261 2241 check_ajax_referer( 'uwp_basic_nonce', 'security' );
2262 2242
2263 - // Check user logged in.
2264 - if ( ! is_user_logged_in() ) {
2265 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Access denied!', 'userswp' ) ) );
2266 - wp_send_json_error( array( 'message' => $message ) );
2267 - }
2268 -
2243 + $htmlvar = esc_sql( strip_tags( $_POST['htmlvar'] ) );
2269 2244 $user_id = ! empty( $_POST['uid'] ) ? absint( $_POST['uid'] ) : 0;
2270 - $htmlvar = ! empty( $_POST['htmlvar'] ) ? sanitize_key( $_POST['htmlvar'] ) : '';
2271 2245
2272 - if ( empty( $user_id ) || empty( $htmlvar ) ) {
2273 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid data!', 'userswp' ) ) );
2274 - wp_send_json_error( array( 'message' => $message ) );
2246 + if ( empty( $user_id ) ) {
2247 + wp_die( -1 );
2275 2248 }
2276 2249
2277 - // Validate the user / admin.
2278 - if ( ! ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) {
2279 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid access!', 'userswp' ) ) );
2280 - wp_send_json_error( array( 'message' => $message ) );
2250 + if ( ! ( is_user_logged_in() && ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) ) {
2251 + wp_send_json_error( __( 'Invalid access!', 'userswp' ) );
2281 2252 }
2282 2253
2254 + // Remove file
2283 2255 if ( $htmlvar == 'banner_thumb' ) {
2284 - $field_key = 'banner';
2256 + $file = uwp_get_usermeta( $user_id, 'banner_thumb' );
2285 2257 $type = 'banner';
2286 - } else if ( $htmlvar == 'avatar_thumb' ) {
2287 - $field_key = 'avatar';
2258 + } elseif ( $htmlvar == 'avatar_thumb' ) {
2259 + $file = uwp_get_usermeta( $user_id, 'avatar_thumb' );
2288 2260 $type = 'avatar';
2289 2261 } else {
2290 - $field_key = $htmlvar;
2262 + $file = '';
2291 2263 $type = '';
2292 2264 }
2293 2265
2294 - $field = $wpdb->get_row( $wpdb->prepare( "SELECT * FROM " . uwp_get_table_prefix() . "uwp_form_fields WHERE htmlvar_name = %s LIMIT 1", $field_key ) );
2295 -
2296 - // Check field exists.
2297 - if ( empty( $field ) ) {
2298 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field!', 'userswp' ) ) );
2299 - wp_send_json_error( array( 'message' => $message ) );
2300 - }
2301 -
2302 - // Validate field access.
2303 - if ( ! empty( $field->for_admin_use ) && ! current_user_can( 'manage_options' ) ) {
2304 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'You are not allowed to perform this action!', 'userswp' ) ) );
2305 - wp_send_json_error( array( 'message' => $message ) );
2306 - }
2307 -
2308 - if ( ! in_array( $field->field_type, array( 'file', 'image' ) ) ) {
2309 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field type!', 'userswp' ) ) );
2310 - wp_send_json_error( array( 'message' => $message ) );
2311 - }
2312 -
2313 - $value = uwp_get_usermeta( $user_id, $htmlvar );
2314 -
2315 2266 uwp_update_usermeta( $user_id, $htmlvar, '' );
2316 2267
2317 - if ( $value && validate_file( $value ) === 0 ) {
2268 + if ( $file ) {
2318 2269 $uploads = wp_upload_dir();
2319 2270 $upload_path = $uploads['basedir'];
2271 + $unlink_file = untrailingslashit( $upload_path ) . '/' . ltrim( $file, '/' );
2320 2272
2321 - if ( strpos( $value, 'http://' ) === 0 || strpos( $value, 'https://' ) === 0 ) {
2322 - // Get the relative url.
2323 - $value = uwp_get_file_relative_url( $value );
2324 - }
2325 -
2326 - $unlink_file = untrailingslashit( $upload_path ) . '/' . trim( $value, '/\\' );
2327 -
2328 2273 if ( is_file( $unlink_file ) && file_exists( $unlink_file ) ) {
2329 - wp_delete_file( $unlink_file );
2274 + @unlink( $unlink_file );
2275 + $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_file );
2330 2276
2331 - // For avatar/banner, also remove the original (non-thumb) file.
2332 - if ( $type ) {
2333 - $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_file );
2334 -
2335 - if ( is_file( $unlink_ori_file ) && file_exists( $unlink_ori_file ) ) {
2336 - wp_delete_file( $unlink_ori_file );
2337 - }
2277 + if ( is_file( $unlink_ori_file ) && file_exists( $unlink_ori_file ) ) {
2278 + @unlink( $unlink_ori_file );
2338 2279 }
2339 2280 }
2340 2281 }
2341 2282
@@ -4369,9 +4310,9 @@
4369 4310 // If no html then we run the standard output.
4370 4311 if ( empty( $html ) ) {
4371 4312
4372 4313 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4373 - $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds margin so we remove ours
4314 + $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds marginso we remove ours
4374 4315 $bs_sr_only = $design_style ? 'sr-only' : '';
4375 4316 $bs_form_control = $design_style ? 'form-control' : '';
4376 4317
4377 4318 ob_start(); // Start buffering;
@@ -4934,13 +4875,13 @@
4934 4875 function (event) {
4935 4876 var $form = $(this).closest('form');
4936 4877 if( ! $form.hasClass('uwp-login-form') ) {
4937 4878 uwp_checkPasswordStrength(
4938 - $form.find('input[name=password]'),
4939 - $form.find('input[name=confirm_password]'),
4940 - $form.find('#uwp-password-strength'),
4941 - $form.find('button[type="submit"], input[type="submit"]'),
4942 - ['black', 'listed', 'word']
4879 + $('input[name=password]', $form), // First password field
4880 + $('input[name=confirm_password]', $form), // Second password field
4881 + $('#uwp-password-strength', $form), // Strength meter
4882 + $('input[type=submit]', $form), // Submit button
4883 + ['black', 'listed', 'word'] // Blacklisted words
4943 4884 );
4944 4885 }
4945 4886 }
4946 4887 );
@@ -4967,15 +4908,12 @@
4967 4908 public function ajax_forgot_password_form() {
4968 4909
4969 4910 // add the modal error container
4970 4911 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
4971 - $args = array(
4972 - 'form_title' => '',
4973 - 'css_class' => ''
4974 - );
4912 +
4975 4913 // get the form
4976 4914 ob_start();
4977 - uwp_get_template( 'bootstrap/forgot.php', $args );
4915 + uwp_get_template( 'bootstrap/forgot.php' );
4978 4916 $form = ob_get_clean();
4979 4917
4980 4918 // bs5
4981 4919 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {