PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.48
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.48
1.2.74 1.2.73 1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.20 1.0.21 All 174 releases
← All changes | includes/class-forms.php +123 -506 1.2.731.2.48 View file →
@@ -102,26 +102,27 @@
102 102 $processed = true;
103 103 }
104 104
105 105 if ( $processed ) {
106 +
106 107 if ( is_wp_error( $errors ) ) {
107 - aui()->alert(
108 - array(
109 - 'type' => 'error',
110 - 'content' => wp_kses_post( $errors->get_error_message() )
111 - ),
112 - true
113 - );
114 - } else if ( $redirect ) {
108 + echo aui()->alert(
109 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
110 + 'type' => 'error',
111 + 'class' => 'text-center',
112 + 'content' => wp_kses_post( $errors->get_error_message() ),
113 + )
114 + );
115 + } elseif ( $redirect ) {
115 116 wp_safe_redirect( $redirect );
116 117 exit();
117 - } else {
118 - aui()->alert(
119 - array(
120 - 'type' => 'success',
121 - 'content' => wp_kses_post( $message )
122 - ),
123 - true
118 + } else {
119 + echo aui()->alert(
120 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
121 + 'type' => 'success',
122 + 'class' => 'text-center',
123 + 'content' => wp_kses_post( $message ),
124 + )
124 125 );
125 126 }
126 127 }
127 128
@@ -195,9 +196,8 @@
195 196 * @since 1.0.0
196 197 */
197 198 public function process_image_crop( $data = array(), $type = 'avatar', $unlink_prev_img = false ) {
198 199 global $wpdb;
199 -
200 200 if ( ! is_user_logged_in() ) {
201 201 return false;
202 202 }
203 203
@@ -204,29 +204,8 @@
204 204 if ( empty( $_POST['uwp_crop_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_crop_nonce'], 'uwp_crop_nonce_' . $type ) ) {
205 205 return;
206 206 }
207 207
208 - $image_url = ! empty( $data['uwp_crop'] ) ? esc_url( $data['uwp_crop'] ) : '';
209 -
210 - if ( empty( $image_url ) ) {
211 - return new WP_Error( 'empty_image', __( 'Upload valid image.', 'userswp' ) );
212 - }
213 -
214 - // Ensure we have a valid URL with an allowed meme type.
215 - $image_url = $this->normalize_url( $image_url );
216 -
217 - $content_url = str_replace( array( 'https://', 'http://' ) , '', untrailingslashit( WP_CONTENT_URL ) );
218 - $_image_url = str_replace( array( 'https://', 'http://' ), '', $image_url );
219 - if ( strpos( $_image_url, $content_url ) !== 0 ) {
220 - return new WP_Error( 'invalid_image', __( 'Invalid image url.', 'userswp' ) );
221 - }
222 -
223 - $filetype = wp_check_filetype( $image_url );
224 -
225 - if ( empty( $filetype['ext'] ) ) {
226 - return new WP_Error( 'invalid_image', __( 'Invalid image type.', 'userswp' ) );
227 - }
228 -
229 208 // If is current user's profile (profile.php)
230 209 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
231 210 $user_id = get_current_user_id();
232 211 // If is another user's profile page
@@ -236,8 +215,21 @@
236 215 } else {
237 216 $user_id = get_current_user_id();
238 217 }
239 218
219 + // Ensure we have a valid URL with an allowed meme type.
220 + $image_url = $this->normalize_url( esc_url( $data['uwp_crop'] ) );
221 + $filetype = wp_check_filetype( $image_url );
222 +
223 + $errors = new WP_Error();
224 + if ( empty( $image_url ) || empty( $filetype['ext'] ) ) {
225 + $errors->add( 'something_wrong', __( 'Something went wrong. Please contact site admin.', 'userswp' ) );
226 + }
227 +
228 + if ( $errors->has_errors() ) {
229 + return $errors;
230 + }
231 +
240 232 // Retrieve current thumbnail.
241 233 $current_field = 'avatar' === $type ? 'avatar_thumb' : 'banner_thumb';
242 234 $current_thumbnail = $this->normalize_url( uwp_get_usermeta( $user_id, $current_field, '' ) );
243 235 $thumb_postfix = '_uwp_' . $type . '_thumb';
@@ -260,14 +252,13 @@
260 252 $ext = $filetype['ext']; // to get extension
261 253 $name = sanitize_file_name( pathinfo( $image_path, PATHINFO_FILENAME ) ); //file name without extension
262 254 $thumb_image_name = $name . $thumb_postfix . '.' . $ext;
263 255 $thumb_image_location = str_replace( $name . '.' . $ext, $thumb_image_name, $image_path );
264 -
265 256 //Get the new coordinates to crop the image.
266 - $x = $data['uwpx'];
267 - $y = $data['uwpy'];
268 - $w = $data['uwpw'];
269 - $h = $data['uwph'];
257 + $x = $data['x'];
258 + $y = $data['y'];
259 + $w = $data['w'];
260 + $h = $data['h'];
270 261 //Scale the image based on cropped width setting
271 262 $scale = $full_width / $w;
272 263 //$scale = 1; // no scaling
273 264
@@ -327,11 +318,8 @@
327 318 *
328 319 */
329 320 public function normalize_url( $url ) {
330 321
331 - if ( empty( $url ) ) {
332 - return '';
333 - }
334 322 // Normalize.
335 323 $url = wp_normalize_path( $url );
336 324
337 325 // Remove query vars.
@@ -360,20 +348,22 @@
360 348 if ( ! is_user_logged_in() ) {
361 349 return false;
362 350 }
363 351
352 + if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type ) ) {
353 + return;
354 + }
355 +
364 356 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
365 357 $user_id = get_current_user_id();
366 - } elseif ( is_admin() && current_user_can( 'manage_options' ) && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
358 + // If is another user's profile page
359 + } elseif ( is_admin() && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
367 360 $user_id = absint( $_GET['user_id'] );
361 + // Otherwise something is wrong.
368 362 } else {
369 363 $user_id = get_current_user_id();
370 364 }
371 365
372 - if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type . '_' . $user_id ) ) {
373 - return;
374 - }
375 -
376 366 $errors = new WP_Error();
377 367 if ( empty( $user_id ) ) {
378 368 $errors->add( 'something_wrong', __( 'Something went wrong. Please try again.', 'userswp' ) );
379 369 }
@@ -533,15 +523,9 @@
533 523 if ( isset( $data['uwp_register_hp'] ) && '' != $data['uwp_register_hp'] ) {
534 524 wp_die( esc_html__( 'No spam please!', 'userswp' ) );
535 525 }
536 526
537 - $form_id = 1;
538 -
539 - if ( ! empty( $data['uwp_register_form_id'] ) ) {
540 - $form_id = (int) $data['uwp_register_form_id'];
541 - }
542 -
543 - if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce-' . $form_id ) ) {
527 + if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce' ) ) {
544 528 $message = aui()->alert(
545 529 array(
546 530 'type' => 'error',
547 531 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
@@ -713,8 +697,14 @@
713 697 'last_name' => esc_attr( $last_name ),
714 698 'user_url' => esc_url_raw( $user_url ),
715 699 );
716 700
701 + $form_id = 1;
702 +
703 + if ( ! empty( $data['uwp_register_form_id'] ) ) {
704 + $form_id = (int) $data['uwp_register_form_id'];
705 + }
706 +
717 707 // Set user role by form.
718 708 $user_role = uwp_get_register_form_by( $form_id, 'user_role' );
719 709
720 710 if ( ! empty( $user_role ) ) {
@@ -1175,11 +1165,8 @@
1175 1165 global $wp2fa;
1176 1166 if ( wp_doing_ajax() && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1177 1167 remove_action( 'wp_login', array( $wp2fa->login, 'wp_login' ), 20 );
1178 1168 }
1179 - if ( wp_doing_ajax() && class_exists( '\WP2FA\Authenticator\Login' ) ) {
1180 - remove_action( 'wp_login', array( 'WP2FA\Authenticator\Login', 'wp_login' ), 20 );
1181 - }
1182 1169
1183 1170 $user = wp_signon(
1184 1171 array(
1185 1172 'user_login' => $result['username'],
@@ -1188,14 +1175,10 @@
1188 1175 )
1189 1176 );
1190 1177
1191 1178 add_action( 'authenticate', 'gglcptch_login_check', 21, 1 );
1192 - if ( wp_doing_ajax() && class_exists( '\WP2FA\Authenticator\Login' ) ) {
1193 - add_action( 'wp_login', array( 'WP2FA\Authenticator\Login', 'wp_login' ), 20, 2 );
1194 - }
1195 1179
1196 - $wp2fa_available = ( isset( $wp2fa ) && ! empty( $wp2fa ) ) || class_exists( '\WP2FA\Authenticator\Login' );
1197 - if ( wp_doing_ajax() && ! is_wp_error( $user ) && $wp2fa_available ) {
1180 + if ( wp_doing_ajax() && ! is_wp_error( $user ) && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1198 1181
1199 1182 $two_fa = $this->check_2fa( $user );
1200 1183 if ( isset( $two_fa ) && ! empty( $two_fa ) ) {
1201 1184 if ( is_wp_error( $two_fa ) ) {
@@ -1216,20 +1199,8 @@
1216 1199 }
1217 1200 }
1218 1201 }
1219 1202
1220 - if ( wp_doing_ajax() && is_wp_error( $user ) && $this->wordfence_2fa_available() ) {
1221 - $wfls_2fa = $this->check_wordfence_2fa( $user, $result );
1222 - if ( ! empty( $wfls_2fa ) ) {
1223 - wp_send_json_success(
1224 - array(
1225 - 'html' => $wfls_2fa,
1226 - 'is_2fa' => true,
1227 - )
1228 - );
1229 - }
1230 - }
1231 -
1232 1203 if ( is_wp_error( $user ) ) {
1233 1204 $message = aui()->alert(
1234 1205 array(
1235 1206 'type' => 'error',
@@ -1297,12 +1268,9 @@
1297 1268
1298 1269 return $errors;
1299 1270 }
1300 1271
1301 - $provider = $this->get_wp2fa_provider_for_user( $user );
1302 - if ( empty( $provider ) ) {
1303 - return;
1304 - }
1272 + $provider = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1305 1273
1306 1274 ob_start();
1307 1275 ?>
1308 1276
@@ -1353,9 +1321,9 @@
1353 1321 echo aui()->input(
1354 1322 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1355 1323 'type' => 'tel',
1356 1324 'id' => 'authcode',
1357 - 'name' => 'authcode',
1325 + 'name' => 'wp-2fa-email-code',
1358 1326 'placeholder' => esc_attr__( 'Verification Code', 'userswp' ),
1359 1327 'value' => '',
1360 1328 'label' => esc_html__( 'Verification Code', 'userswp' ),
1361 1329 'extra_attributes' => array(
@@ -1390,9 +1358,9 @@
1390 1358 </form>
1391 1359 </div>
1392 1360
1393 1361 <?php
1394 - $codes_remaining = $this->get_wp2fa_backup_codes_remaining( $user );
1362 + $codes_remaining = \WP2FA\Authenticator\Backup_Codes::codes_remaining_for_user( $user );
1395 1363 if ( isset( $codes_remaining ) && $codes_remaining > 0 ) {
1396 1364 ?>
1397 1365 <div class="uwp-2fa-methods-wrap" style="display:none;">
1398 1366 <form name="validate_2fa_backup_codes_form" id="validate_2fa_backup_codes_form"
@@ -1448,247 +1416,9 @@
1448 1416
1449 1417 return ob_get_clean();
1450 1418 }
1451 1419
1452 - /**
1453 - * Checks if the Wordfence Login Security module (2FA) is available.
1454 - *
1455 - * @since 1.2.5
1456 - * @package userswp
1457 - *
1458 - * @return bool
1459 - */
1460 - public function wordfence_2fa_available() {
1461 - return class_exists( '\WordfenceLS\Controller_Users' ) && class_exists( '\WordfenceLS\Controller_TOTP' );
1462 - }
1463 -
1464 - /**
1465 - * Checks whether Wordfence's 2FA requires a verification code for the
1466 - * failed login attempt and, if so, returns the markup for the code entry form.
1467 - *
1468 - * @since 1.2.5
1469 - * @package userswp
1470 - *
1471 - * @param WP_Error $error The error returned by wp_signon().
1472 - * @param array $result The validated login fields (username/password).
1473 - *
1474 - * @return string|void The 2FA form markup, or nothing if not applicable.
1475 - */
1476 - public function check_wordfence_2fa( $error, $result ) {
1477 - if ( 1 == uwp_get_option( 'disable_wordfence_2fa' ) ) {
1478 - return;
1479 - }
1480 -
1481 - if ( ! $this->wordfence_2fa_available() ) {
1482 - return;
1483 - }
1484 -
1485 - if ( ! is_wp_error( $error ) || 'wfls_twofactor_required' !== $error->get_error_code() ) {
1486 - return;
1487 - }
1488 -
1489 - $username = ! empty( $result['username'] ) ? $result['username'] : '';
1490 - if ( empty( $username ) ) {
1491 - return;
1492 - }
1493 -
1494 - $user = is_email( $username ) ? get_user_by( 'email', $username ) : get_user_by( 'login', $username );
1495 - if ( ! $user ) {
1496 - return;
1497 - }
1498 -
1499 - if ( ! \WordfenceLS\Controller_Users::shared()->has_2fa_active( $user ) ) {
1500 - return;
1501 - }
1502 -
1503 - if ( \WordfenceLS\Controller_Users::shared()->has_remembered_2fa( $user ) ) {
1504 - return;
1505 - }
1506 -
1507 - $login_nonce = wp_create_nonce( 'uwp-wfls-2fa-' . $user->ID );
1508 -
1509 - ob_start();
1510 - ?>
1511 -
1512 - <div class="uwp-2fa-methods-wrap">
1513 - <form name="validate_2fa_form" id="validate_2fa_form" class="validate_2fa_form" action="" method="post"
1514 - autocomplete="off">
1515 - <input type="hidden" name="provider" id="provider" value="wordfence"/>
1516 - <input type="hidden" name="uwp-auth-id" id="uwp-auth-id" value="<?php echo esc_attr( $user->ID ); ?>"/>
1517 - <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1518 - value="<?php echo esc_attr( $login_nonce ); ?>"/>
1519 -
1520 - <p><?php esc_html_e( 'Please enter the authentication code from your two-factor authentication app, or a recovery code, to login:', 'userswp' ); ?></p>
1521 -
1522 - <?php
1523 - echo aui()->input(
1524 - array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1525 - 'type' => 'text',
1526 - 'id' => 'authcode',
1527 - 'name' => 'authcode',
1528 - 'placeholder' => esc_attr__( 'Authentication Code', 'userswp' ),
1529 - 'value' => '',
1530 - 'label' => esc_html__( 'Authentication Code', 'userswp' ),
1531 - 'extra_attributes' => array(
1532 - 'autocomplete' => 'one-time-code',
1533 - ),
1534 - )
1535 - );
1536 -
1537 - echo aui()->button(
1538 - array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1539 - 'type' => 'submit',
1540 - 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1541 - 'name' => 'submit',
1542 - 'icon' => '',
1543 - 'content' => esc_html__( 'Log In', 'userswp' ),
1544 - )
1545 - );
1546 - ?>
1547 - </form>
1548 - </div>
1549 -
1550 - <?php
1551 - return ob_get_clean();
1552 - }
1553 -
1554 - public function get_wp2fa_provider_for_user( $user ) {
1555 - if ( class_exists( '\WP2FA\Authenticator\Login' ) && method_exists( '\WP2FA\Authenticator\Login', 'get_available_providers_for_user' ) ) {
1556 - $provider = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1557 - if ( is_array( $provider ) ) {
1558 - $provider = key( $provider );
1559 - }
1560 -
1561 - return $provider;
1562 - }
1563 -
1564 - if ( class_exists( '\WP2FA\Admin\Helpers\User_Helper' ) && method_exists( '\WP2FA\Admin\Helpers\User_Helper', 'get_enabled_method_for_user' ) ) {
1565 - return \WP2FA\Admin\Helpers\User_Helper::get_enabled_method_for_user( $user );
1566 - }
1567 -
1568 - return '';
1569 - }
1570 -
1571 - public function get_wp2fa_backup_codes_remaining( $user ) {
1572 - if ( class_exists( '\WP2FA\Methods\Backup_Codes' ) && method_exists( '\WP2FA\Methods\Backup_Codes', 'codes_remaining_for_user' ) ) {
1573 - return \WP2FA\Methods\Backup_Codes::codes_remaining_for_user( $user );
1574 - }
1575 -
1576 - if ( class_exists( '\WP2FA\Authenticator\Backup_Codes' ) && method_exists( '\WP2FA\Authenticator\Backup_Codes', 'codes_remaining_for_user' ) ) {
1577 - return \WP2FA\Authenticator\Backup_Codes::codes_remaining_for_user( $user );
1578 - }
1579 -
1580 - return 0;
1581 - }
1582 -
1583 - public function validate_wp2fa_totp_authentication( $user ) {
1584 - if ( class_exists( '\WP2FA\Methods\TOTP' ) && method_exists( '\WP2FA\Methods\TOTP', 'validate_totp_authentication' ) ) {
1585 - return \WP2FA\Methods\TOTP::validate_totp_authentication( $user );
1586 - }
1587 -
1588 - if ( class_exists( '\WP2FA\Authenticator\Login' ) && method_exists( '\WP2FA\Authenticator\Login', 'validate_totp_authentication' ) ) {
1589 - return \WP2FA\Authenticator\Login::validate_totp_authentication( $user );
1590 - }
1591 -
1592 - return false;
1593 - }
1594 -
1595 - public function validate_wp2fa_email_authentication( $user ) {
1596 - if ( class_exists( '\WP2FA\Authenticator\Login' ) && method_exists( '\WP2FA\Authenticator\Login', 'validate_email_authentication' ) ) {
1597 - return \WP2FA\Authenticator\Login::validate_email_authentication( $user );
1598 - }
1599 -
1600 - if ( class_exists( '\WP2FA\Authenticator\Authentication' ) && method_exists( '\WP2FA\Authenticator\Authentication', 'validate_token' ) && isset( $_REQUEST['authcode'] ) ) {
1601 - return \WP2FA\Authenticator\Authentication::validate_token( $user, sanitize_text_field( wp_unslash( $_REQUEST['authcode'] ) ) );
1602 - }
1603 -
1604 - return false;
1605 - }
1606 -
1607 - public function validate_wp2fa_backup_codes( $user ) {
1608 - if ( class_exists( '\WP2FA\Methods\Backup_Codes' ) && method_exists( '\WP2FA\Methods\Backup_Codes', 'validate_backup_codes' ) ) {
1609 - return \WP2FA\Methods\Backup_Codes::validate_backup_codes( $user );
1610 - }
1611 -
1612 - if ( class_exists( '\WP2FA\Authenticator\Backup_Codes' ) && method_exists( '\WP2FA\Authenticator\Backup_Codes', 'validate_backup_codes' ) ) {
1613 - return \WP2FA\Authenticator\Backup_Codes::validate_backup_codes( $user );
1614 - }
1615 -
1616 - return false;
1617 - }
1618 -
1619 - /**
1620 - * Validates the Wordfence 2FA code submitted from the uwp-2fa form and,
1621 - * if valid, completes the login by setting the auth cookie.
1622 - *
1623 - * @since 1.2.5
1624 - * @package userswp
1625 - *
1626 - * @param WP_User $user The user attempting to complete 2FA login.
1627 - *
1628 - * @return void
1629 - */
1630 - public function process_login_wordfence_2fa( $user ) {
1631 - if ( ! $this->wordfence_2fa_available() ) {
1632 - $message = aui()->alert(
1633 - array(
1634 - 'type' => 'error',
1635 - 'content' => __( 'Invalid request! Please try again.', 'userswp' ),
1636 - )
1637 - );
1638 -
1639 - wp_send_json_error( array( 'message' => $message ) );
1640 - }
1641 -
1642 - $nonce = ( isset( $_POST['wp-auth-nonce'] ) ) ? sanitize_textarea_field( wp_unslash( $_POST['wp-auth-nonce'] ) ) : '';
1643 -
1644 - if ( ! wp_verify_nonce( $nonce, 'uwp-wfls-2fa-' . $user->ID ) ) {
1645 - $message = aui()->alert(
1646 - array(
1647 - 'type' => 'error',
1648 - 'content' => __( 'Invalid request! Please try again.', 'userswp' ),
1649 - )
1650 - );
1651 -
1652 - wp_send_json_error( array( 'message' => $message ) );
1653 - }
1654 -
1655 - $code = isset( $_POST['authcode'] ) ? sanitize_text_field( wp_unslash( $_POST['authcode'] ) ) : '';
1656 -
1657 - if ( empty( $code ) || true !== \WordfenceLS\Controller_TOTP::shared()->validate_2fa( $user, $code ) ) {
1658 - do_action( 'wp_login_failed', $user->user_login );
1659 -
1660 - $message = aui()->alert(
1661 - array(
1662 - 'type' => 'error',
1663 - 'content' => __( 'Invalid verification code.', 'userswp' ),
1664 - )
1665 - );
1666 -
1667 - wp_send_json_error( array( 'message' => $message ) );
1668 - }
1669 -
1670 - $remember = ( isset( $_REQUEST['rememberme'] ) ) ? filter_var( $_REQUEST['rememberme'], FILTER_VALIDATE_BOOLEAN ) : false;
1671 -
1672 - // Complete the login the same way wp_signon() would have, now that 2FA has been verified.
1673 - wp_set_auth_cookie( $user->ID, $remember );
1674 - wp_set_current_user( $user->ID );
1675 -
1676 - do_action( 'wp_login', $user->user_login, $user );
1677 -
1678 - $message = aui()->alert(
1679 - array(
1680 - 'type' => 'success',
1681 - 'content' => __( 'Validation successful. Redirecting...', 'userswp' ),
1682 - )
1683 - );
1684 -
1685 - wp_send_json_success( array( 'message' => $message ) );
1686 - }
1687 -
1688 1420 public function process_login_2fa() {
1689 - global $wp2fa;
1690 -
1691 1421 if ( ! isset( $_POST['uwp-auth-id'], $_POST['wp-auth-nonce'] ) ) {
1692 1422 return;
1693 1423 }
1694 1424
@@ -1693,70 +1423,46 @@
1693 1423 }
1694 1424
1695 1425 $auth_id = (int) $_POST['uwp-auth-id'];
1696 1426 $user = get_userdata( $auth_id );
1697 -
1698 1427 if ( ! $user ) {
1699 1428 $message = aui()->alert(
1700 - array(
1429 + array(
1701 1430 'type' => 'error',
1702 1431 'content' => __( 'Invalid user data. Please try again.', 'userswp' ),
1703 - )
1432 + )
1704 1433 );
1705 1434
1706 1435 wp_send_json_error( array( 'message' => $message ) );
1707 1436 }
1708 1437
1709 - if ( isset( $_POST['provider'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing
1710 - $provider = sanitize_textarea_field( wp_unslash( $_POST['provider'] ) ); // phpcs:ignore WordPress.Security.NonceVerification.Missing
1711 - } else {
1712 - $provider = '';
1713 - }
1438 + global $wp2fa;
1714 1439
1715 - if ( 'wordfence' === $provider ) {
1716 - $this->process_login_wordfence_2fa( $user );
1717 -
1718 - return;
1719 - }
1720 -
1721 1440 $nonce = ( isset( $_POST['wp-auth-nonce'] ) ) ? sanitize_textarea_field( wp_unslash( $_POST['wp-auth-nonce'] ) ) : '';
1441 + if ( true !== \WP2FA\Authenticator\Login::verify_login_nonce( $user->ID, $nonce ) ) {
1722 1442
1723 - if ( true !== \WP2FA\Authenticator\Login::verify_login_nonce( $user->ID, $nonce ) ) {
1724 1443 $message = aui()->alert(
1725 - array(
1444 + array(
1726 1445 'type' => 'error',
1727 1446 'content' => __( 'Invalid request! Please try again.', 'userswp' ),
1728 - )
1447 + )
1729 1448 );
1730 1449
1731 1450 wp_send_json_error( array( 'message' => $message ) );
1732 1451 }
1733 1452
1734 - $error = '';
1735 -
1736 - try {
1737 - $is_enabled = \WP2FA\Admin\Controllers\Settings::is_provider_enabled_for_role( \WP2FA\Admin\Helpers\User_Helper::get_user_role( $user ), $provider );
1738 -
1739 - if ( ! $is_enabled ) {
1740 - $error = __( 'Invalid 2FA provider for user.', 'userswp' );
1453 + if ( isset( $_POST['provider'] ) ) {
1454 + $provider = sanitize_textarea_field( wp_unslash( $_POST['provider'] ) );
1455 + $providers = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1456 + if ( isset( $providers[ $provider ] ) ) {
1457 + $provider = $providers[ $provider ];
1458 + } elseif ( isset( $provider ) ) {
1459 + $provider = $provider;
1460 + } else {
1461 + $provider = $provider;
1741 1462 }
1742 - } catch ( \Exception $e ) {
1743 - $error = $e->getMessage();
1744 1463 }
1745 1464
1746 - if ( $error ) {
1747 - do_action( 'wp_login_failed', $user->user_login );
1748 -
1749 - $message = aui()->alert(
1750 - array(
1751 - 'type' => 'error',
1752 - 'content' => $error
1753 - )
1754 - );
1755 -
1756 - wp_send_json_error( array( 'message' => $message ) );
1757 - }
1758 -
1759 1465 // If this is an email login, or if the user failed validation previously, lets send the code to the user.
1760 1466 if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::pre_process_email_authentication( $user ) ) {
1761 1467
1762 1468 }
@@ -1761,16 +1467,17 @@
1761 1467
1762 1468 }
1763 1469
1764 1470 // Validate TOTP.
1765 - if ( 'totp' === $provider && true !== $this->validate_wp2fa_totp_authentication( $user ) ) {
1471 + if ( 'totp' === $provider && true !== \WP2FA\Authenticator\Login::validate_totp_authentication( $user ) ) {
1472 +
1766 1473 do_action( 'wp_login_failed', $user->user_login );
1767 1474
1768 1475 $message = aui()->alert(
1769 - array(
1476 + array(
1770 1477 'type' => 'error',
1771 1478 'content' => __( 'Invalid verification code.', 'userswp' ),
1772 - )
1479 + )
1773 1480 );
1774 1481
1775 1482 wp_send_json_error( array( 'message' => $message ) );
1776 1483 }
@@ -1775,26 +1482,27 @@
1775 1482 wp_send_json_error( array( 'message' => $message ) );
1776 1483 }
1777 1484
1778 1485 // Validate Email.
1779 - if ( 'email' === $provider && true !== $this->validate_wp2fa_email_authentication( $user ) ) {
1486 + if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::validate_email_authentication( $user ) ) {
1487 +
1780 1488 do_action( 'wp_login_failed', $user->user_login );
1781 1489
1782 1490 if ( isset( $_REQUEST['wp-2fa-email-code-resend'] ) && 1 == $_REQUEST['wp-2fa-email-code-resend'] ) {
1783 1491 $message = aui()->alert(
1784 - array(
1492 + array(
1785 1493 'type' => 'info',
1786 1494 'content' => __( 'A new code has been sent.', 'userswp' ),
1787 - )
1495 + )
1788 1496 );
1789 1497
1790 1498 wp_send_json_error( array( 'message' => $message ) );
1791 1499 } else {
1792 1500 $message = aui()->alert(
1793 - array(
1501 + array(
1794 1502 'type' => 'error',
1795 1503 'content' => __( 'Invalid verification code.', 'userswp' ),
1796 - )
1504 + )
1797 1505 );
1798 1506
1799 1507 wp_send_json_error( array( 'message' => $message ) );
1800 1508 }
@@ -1800,16 +1508,17 @@
1800 1508 }
1801 1509 }
1802 1510
1803 1511 // Backup Codes.
1804 - if ( 'backup_codes' === $provider && true !== $this->validate_wp2fa_backup_codes( $user ) ) {
1512 + if ( 'backup_codes' === $provider && true !== \WP2FA\Authenticator\Login::validate_backup_codes( $user ) ) {
1513 +
1805 1514 do_action( 'wp_login_failed', $user->user_login );
1806 1515
1807 1516 $message = aui()->alert(
1808 - array(
1517 + array(
1809 1518 'type' => 'error',
1810 1519 'content' => __( 'Invalid backup code.', 'userswp' ),
1811 - )
1520 + )
1812 1521 );
1813 1522
1814 1523 wp_send_json_error( array( 'message' => $message ) );
1815 1524 }
@@ -1817,9 +1526,8 @@
1817 1526 \WP2FA\Authenticator\Login::delete_login_nonce( $user->ID );
1818 1527
1819 1528 $rememberme = false;
1820 1529 $remember = ( isset( $_REQUEST['rememberme'] ) ) ? filter_var( $_REQUEST['rememberme'], FILTER_VALIDATE_BOOLEAN ) : '';
1821 -
1822 1530 if ( ! empty( $remember ) ) {
1823 1531 $rememberme = true;
1824 1532 }
1825 1533
@@ -1826,17 +1534,13 @@
1826 1534 wp_set_auth_cookie( $user->ID, $rememberme );
1827 1535
1828 1536 do_action( 'two_factor_user_authenticated', $user );
1829 1537
1830 - if ( defined( 'WP_2FA_PREFIX' ) ) {
1831 - do_action( WP_2FA_PREFIX . 'user_authenticated', $user );
1832 - }
1833 -
1834 1538 $message = aui()->alert(
1835 - array(
1539 + array(
1836 1540 'type' => 'success',
1837 1541 'content' => __( 'Validation successful. Redirecting...', 'userswp' ),
1838 - )
1542 + )
1839 1543 );
1840 1544
1841 1545 wp_send_json_success( array( 'message' => $message ) );
1842 1546 }
@@ -1933,12 +1637,9 @@
1933 1637 }
1934 1638
1935 1639 do_action( 'uwp_after_validate', $result, 'forgot', $data );
1936 1640
1937 - $login_or_email = trim( $data['email'] );
1938 - $user_data = is_email( $login_or_email )
1939 - ? get_user_by( 'email', $login_or_email )
1940 - : get_user_by( 'login', $login_or_email );
1641 + $user_data = get_user_by( 'email', $data['email'] );
1941 1642
1942 1643 // if no user we fake it and bail
1943 1644 if ( ! $user_data ) {
1944 1645 $args = apply_filters(
@@ -1944,9 +1645,9 @@
1944 1645 $args = apply_filters(
1945 1646 'uwp_forgot_error_message',
1946 1647 array(
1947 1648 'type' => 'error',
1948 - 'content' => __( 'Invalid username/email or user doesn\'t exist.', 'userswp' ),
1649 + 'content' => __( 'Invalid email or user doesn\'t exists.', 'userswp' ),
1949 1650 )
1950 1651 );
1951 1652
1952 1653 $message = aui()->alert( $args );
@@ -1961,21 +1662,12 @@
1961 1662
1962 1663 // make sure user account is active before account reset
1963 1664 $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true );
1964 1665 if ( $mod_value == 'email_unconfirmed' ) {
1965 - $resend_link = uwp_get_forgot_page_url();
1966 - $resend_link = add_query_arg(
1967 - array(
1968 - 'user_id' => $user_data->ID,
1969 - 'action' => 'uwp_resend',
1970 - '_nonce' => wp_create_nonce('uwp_resend'),
1971 - ),
1972 - $resend_link
1973 - );
1974 1666 $message = aui()->alert(
1975 1667 array(
1976 1668 'type' => 'error',
1977 - 'content' => sprintf(__('Your account is not activated yet. Please activate your account first. <a href="%s">Resend</a>.', 'userswp'), $resend_link),
1669 + 'content' => __( 'Your account is not activated yet. Please activate your account first.', 'userswp' ),
1978 1670 )
1979 1671 );
1980 1672 if ( wp_doing_ajax() ) {
1981 1673 wp_send_json_error( $message );
@@ -1980,8 +1672,9 @@
1980 1672 if ( wp_doing_ajax() ) {
1981 1673 wp_send_json_error( $message );
1982 1674 } else {
1983 1675 $uwp_notices[] = array( 'forgot' => $message );
1676 +
1984 1677 return;
1985 1678 }
1986 1679 }
1987 1680
@@ -1996,8 +1689,9 @@
1996 1689 }
1997 1690
1998 1691 $as_password = apply_filters( 'uwp_forgot_message_as_password', false );
1999 1692
1693 + global $wpdb, $wp_hasher;
2000 1694 $reset_link = '';
2001 1695
2002 1696 if ( $as_password ) {
2003 1697 $new_pass = wp_generate_password( 12, false );
@@ -2009,21 +1703,17 @@
2009 1703 $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
2010 1704 $message .= '<p>' . sprintf( __( 'Password: %s', 'userswp' ), $new_pass ) . '</p>';
2011 1705
2012 1706 } else {
2013 - // Use WordPress core to generate, hash (wp_fast_hash in WP 6.8+), and store the reset key.
2014 - // This ensures compatibility with check_password_reset_key() on all WP versions.
2015 - $key = get_password_reset_key( $user_data );
1707 + $key = wp_generate_password( 20, false );
1708 + do_action( 'retrieve_password_key', $user_data->user_login, $key );
2016 1709
2017 - if ( is_wp_error( $key ) ) {
2018 - if ( wp_doing_ajax() ) {
2019 - wp_send_json_error( $key->get_error_message() );
2020 - } else {
2021 - $uwp_notices[] = array( 'forgot' => aui()->alert( array( 'type' => 'error', 'content' => $key->get_error_message() ) ) );
2022 - return;
2023 - }
1710 + if ( empty( $wp_hasher ) ) {
1711 + require_once ABSPATH . 'wp-includes/class-phpass.php';
1712 + $wp_hasher = new PasswordHash( 8, true );
2024 1713 }
2025 -
1714 + $hashed = $wp_hasher->HashPassword( $key );
1715 + $wpdb->update( $wpdb->users, array( 'user_activation_key' => time() . ':' . $hashed ), array( 'user_login' => $user_data->user_login ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
2026 1716 $message = '<p>' . __( 'You have requested to reset your password for the following account:', 'userswp' ) . '</p>';
2027 1717 $message .= home_url( '/' ) . '</p>';
2028 1718 $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
2029 1719 $message .= '<p>' . __( 'If this was by mistake, just ignore this email and nothing will happen.', 'userswp' ) . '</p>';
@@ -2316,21 +2006,8 @@
2316 2006 unset( $uploads_result[ $upload_file_key ] );
2317 2007 }
2318 2008 }
2319 2009
2320 - global $wpdb;
2321 - $file_field_names = $wpdb->get_col(
2322 - $wpdb->prepare(
2323 - "SELECT htmlvar_name FROM " . uwp_get_table_prefix() . "uwp_form_fields WHERE form_type = %s AND field_type IN ('file','image')",
2324 - 'account'
2325 - )
2326 - );
2327 - foreach ( $file_field_names as $file_field_name ) {
2328 - if ( isset( $result[ $file_field_name ] ) && ! isset( $uploads_result[ $file_field_name ] ) ) {
2329 - unset( $result[ $file_field_name ] );
2330 - }
2331 - }
2332 -
2333 2010 $result = array_merge( $result, $uploads_result );
2334 2011
2335 2012 $args = array(
2336 2013 'ID' => get_current_user_id(),
@@ -2560,94 +2237,46 @@
2560 2237 * @package userswp
2561 2238 * @since 1.0.0
2562 2239 */
2563 2240 public function upload_file_remove() {
2564 - global $wpdb;
2565 -
2566 2241 check_ajax_referer( 'uwp_basic_nonce', 'security' );
2567 2242
2568 - // Check user logged in.
2569 - if ( ! is_user_logged_in() ) {
2570 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Access denied!', 'userswp' ) ) );
2571 - wp_send_json_error( array( 'message' => $message ) );
2572 - }
2573 -
2243 + $htmlvar = esc_sql( strip_tags( $_POST['htmlvar'] ) );
2574 2244 $user_id = ! empty( $_POST['uid'] ) ? absint( $_POST['uid'] ) : 0;
2575 - $htmlvar = ! empty( $_POST['htmlvar'] ) ? sanitize_key( $_POST['htmlvar'] ) : '';
2576 2245
2577 - if ( empty( $user_id ) || empty( $htmlvar ) ) {
2578 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid data!', 'userswp' ) ) );
2579 - wp_send_json_error( array( 'message' => $message ) );
2246 + if ( empty( $user_id ) ) {
2247 + wp_die( -1 );
2580 2248 }
2581 2249
2582 - // Validate the user / admin.
2583 - if ( ! ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) {
2584 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid access!', 'userswp' ) ) );
2585 - wp_send_json_error( array( 'message' => $message ) );
2250 + if ( ! ( is_user_logged_in() && ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) ) {
2251 + wp_send_json_error( __( 'Invalid access!', 'userswp' ) );
2586 2252 }
2587 2253
2254 + // Remove file
2588 2255 if ( $htmlvar == 'banner_thumb' ) {
2589 - $field_key = 'banner';
2256 + $file = uwp_get_usermeta( $user_id, 'banner_thumb' );
2590 2257 $type = 'banner';
2591 - } else if ( $htmlvar == 'avatar_thumb' ) {
2592 - $field_key = 'avatar';
2258 + } elseif ( $htmlvar == 'avatar_thumb' ) {
2259 + $file = uwp_get_usermeta( $user_id, 'avatar_thumb' );
2593 2260 $type = 'avatar';
2594 2261 } else {
2595 - $field_key = $htmlvar;
2262 + $file = '';
2596 2263 $type = '';
2597 2264 }
2598 2265
2599 - $field = $wpdb->get_row( $wpdb->prepare( "SELECT * FROM " . uwp_get_table_prefix() . "uwp_form_fields WHERE htmlvar_name = %s LIMIT 1", $field_key ) );
2600 -
2601 - // Check field exists.
2602 - if ( empty( $field ) ) {
2603 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field!', 'userswp' ) ) );
2604 - wp_send_json_error( array( 'message' => $message ) );
2605 - }
2606 -
2607 - // Validate field access.
2608 - if ( ! empty( $field->for_admin_use ) && ! current_user_can( 'manage_options' ) ) {
2609 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'You are not allowed to perform this action!', 'userswp' ) ) );
2610 - wp_send_json_error( array( 'message' => $message ) );
2611 - }
2612 -
2613 - if ( ! in_array( $field->field_type, array( 'file', 'image' ) ) ) {
2614 - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field type!', 'userswp' ) ) );
2615 - wp_send_json_error( array( 'message' => $message ) );
2616 - }
2617 -
2618 - $value = uwp_get_usermeta( $user_id, $htmlvar );
2619 -
2620 2266 uwp_update_usermeta( $user_id, $htmlvar, '' );
2621 2267
2622 - if ( $value && validate_file( $value ) === 0 ) {
2268 + if ( $file ) {
2623 2269 $uploads = wp_upload_dir();
2624 2270 $upload_path = $uploads['basedir'];
2271 + $unlink_file = untrailingslashit( $upload_path ) . '/' . ltrim( $file, '/' );
2625 2272
2626 - if ( strpos( $value, 'http://' ) === 0 || strpos( $value, 'https://' ) === 0 ) {
2627 - // Get the relative url.
2628 - $value = uwp_get_file_relative_url( $value );
2629 - }
2273 + if ( is_file( $unlink_file ) && file_exists( $unlink_file ) ) {
2274 + @unlink( $unlink_file );
2275 + $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_file );
2630 2276
2631 - $unlink_file = untrailingslashit( $upload_path ) . '/' . trim( $value, '/\\' );
2632 -
2633 - // Canonicalize and enforce containment inside the uploads directory before deleting.
2634 - $real_upload_path = realpath( $upload_path );
2635 - $real_unlink_file = realpath( $unlink_file );
2636 -
2637 - if ( $real_upload_path && $real_unlink_file && is_file( $real_unlink_file )
2638 - && strpos( $real_unlink_file, $real_upload_path . DIRECTORY_SEPARATOR ) === 0 ) {
2639 - wp_delete_file( $real_unlink_file );
2640 -
2641 - // For avatar/banner, also remove the original (non-thumb) file.
2642 - if ( $type ) {
2643 - $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $real_unlink_file );
2644 - $real_unlink_ori_file = realpath( $unlink_ori_file );
2645 -
2646 - if ( $real_unlink_ori_file && is_file( $real_unlink_ori_file )
2647 - && strpos( $real_unlink_ori_file, $real_upload_path . DIRECTORY_SEPARATOR ) === 0 ) {
2648 - wp_delete_file( $real_unlink_ori_file );
2649 - }
2277 + if ( is_file( $unlink_ori_file ) && file_exists( $unlink_ori_file ) ) {
2278 + @unlink( $unlink_ori_file );
2650 2279 }
2651 2280 }
2652 2281 }
2653 2282
@@ -4129,26 +3758,17 @@
4129 3758 $site_title = uwp_get_form_label( $field );
4130 3759 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4131 3760 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4132 3761
4133 - $is_forgot_email = ( $form_type === 'forgot' && $field->htmlvar_name === 'email' );
4134 - $input_type = $is_forgot_email ? 'text' : 'email';
4135 - if ( $is_forgot_email ) {
4136 - $site_title = __( 'Username or Email', 'userswp' );
4137 - $placeholder = $site_title . ( ! empty( $field->is_required ) ? ' *' : '' );
4138 - } else {
4139 - $placeholder = uwp_get_field_placeholder( $field );
4140 - }
4141 -
4142 3762 if ( $design_style ) {
4143 3763 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4144 3764
4145 3765 echo aui()->input(
4146 3766 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4147 - 'type' => $input_type,
3767 + 'type' => 'email',
4148 3768 'id' => esc_attr( $field->htmlvar_name ),
4149 3769 'name' => esc_attr( $field->htmlvar_name ),
4150 - 'placeholder' => esc_attr( $placeholder ),
3770 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
4151 3771 'title' => esc_html( $site_title ),
4152 3772 'value' => esc_attr( wp_unslash( $value ) ),
4153 3773 'required' => (bool) $field->is_required,
4154 3774 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
@@ -4184,9 +3804,9 @@
4184 3804
4185 3805 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4186 3806 class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
4187 3807 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4188 - placeholder="<?php echo esc_attr( $placeholder ); ?>"
3808 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4189 3809 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
4190 3810 title="<?php echo esc_attr( $site_title ); ?>"
4191 3811 <?php
4192 3812 if ( $field->is_required == 1 ) {
@@ -4192,9 +3812,9 @@
4192 3812 if ( $field->is_required == 1 ) {
4193 3813 echo 'required="required"';
4194 3814 }
4195 3815 ?>
4196 - type="<?php echo esc_attr( $input_type ); ?>"
3816 + type="email"
4197 3817 />
4198 3818 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4199 3819 <?php if ( $field->is_required ) { ?>
4200 3820 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
@@ -4690,9 +4310,9 @@
4690 4310 // If no html then we run the standard output.
4691 4311 if ( empty( $html ) ) {
4692 4312
4693 4313 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4694 - $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds margin so we remove ours
4314 + $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds marginso we remove ours
4695 4315 $bs_sr_only = $design_style ? 'sr-only' : '';
4696 4316 $bs_form_control = $design_style ? 'form-control' : '';
4697 4317
4698 4318 ob_start(); // Start buffering;
@@ -5255,13 +4875,13 @@
5255 4875 function (event) {
5256 4876 var $form = $(this).closest('form');
5257 4877 if( ! $form.hasClass('uwp-login-form') ) {
5258 4878 uwp_checkPasswordStrength(
5259 - $form.find('input[name=password]'),
5260 - $form.find('input[name=confirm_password]'),
5261 - $form.find('#uwp-password-strength'),
5262 - $form.find('button[type="submit"], input[type="submit"]'),
5263 - ['black', 'listed', 'word']
4879 + $('input[name=password]', $form), // First password field
4880 + $('input[name=confirm_password]', $form), // Second password field
4881 + $('#uwp-password-strength', $form), // Strength meter
4882 + $('input[type=submit]', $form), // Submit button
4883 + ['black', 'listed', 'word'] // Blacklisted words
5264 4884 );
5265 4885 }
5266 4886 }
5267 4887 );
@@ -5288,15 +4908,12 @@
5288 4908 public function ajax_forgot_password_form() {
5289 4909
5290 4910 // add the modal error container
5291 4911 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
5292 - $args = array(
5293 - 'form_title' => '',
5294 - 'css_class' => ''
5295 - );
4912 +
5296 4913 // get the form
5297 4914 ob_start();
5298 - uwp_get_template( 'bootstrap/forgot.php', $args );
4915 + uwp_get_template( 'bootstrap/forgot.php' );
5299 4916 $form = ob_get_clean();
5300 4917
5301 4918 // bs5
5302 4919 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {