PluginProbe
weForms – Easy Drag & Drop Contact Form Builder For WordPress / 1.5.1
weForms – Easy Drag & Drop Contact Form Builder For WordPress v1.5.1
1.6.7 1.6.8 1.6.9 1.6.12 1.6.13 1.6.14 1.6.15 1.6.16 1.6.17 1.6.18 1.6.19 1.6.2 1.6.20 1.6.21 1.6.22 1.6.23 1.6.24 1.6.25 1.6.26 1.6.27 1.6.28 1.6.3 1.6.4 1.6.5 1.6.6 All 74 releases
← All changes | includes/class-ajax.php +69 -99 1.6.271.5.1 View file →
@@ -108,12 +108,9 @@
108 108 $settings = array();
109 109 $integrations = array();
110 110
111 111 if ( isset( $post_data['settings'] ) ) {
112 - $settings = json_decode( $post_data['settings'], true );
113 - $settings['message'] = sanitize_text_field( $settings['message'] );
114 - $settings['url'] = sanitize_url( $settings['url'] );
115 - $settings['limit_message'] = sanitize_text_field( $settings['limit_message'] );
112 + $settings = (array) json_decode( $post_data['settings'] );
116 113 } else {
117 114 $settings = isset( $form_data['wpuf_settings'] ) ? $form_data['wpuf_settings'] : [];
118 115 }
119 116
@@ -120,8 +117,11 @@
120 117 if ( isset( $post_data['integrations'] ) ) {
121 118 $integrations = (array) json_decode( $post_data['integrations'] );
122 119 }
123 120
121 + // $form_fields = wp_unslash( $form_fields );
122 + // $notifications = wp_unslash( $notifications );
123 +
124 124 $form_fields = json_decode( $form_fields, true );
125 125 $notifications = json_decode( $notifications, true );
126 126 $data = [
127 127 'form_id' => absint( $form_data['wpuf_form_id'] ),
@@ -134,22 +134,9 @@
134 134 ];
135 135
136 136 $form_fields = weforms()->form->save( $data );
137 137
138 - // Update Old Entry meta_key if changed
139 - $form_id = $form_data['wpuf_form_id'];
140 - $form = weforms()->form->get( $form_id );
141 -
142 - $form->maybe_update_entries( $form_fields );
143 -
144 - do_action( 'weforms_update_form', $form_data['wpuf_form_id'], $form_fields, $settings );
145 -
146 - wp_send_json_success(
147 - array(
148 - 'form_fields' => $form_fields,
149 - 'settings' => $settings,
150 - )
151 - );
138 + wp_send_json_success( [ 'form_fields' => $form_fields ] );
152 139 }
153 140
154 141 /**
155 142 * Get all contact forms
@@ -519,10 +506,9 @@
519 506 $metadata = $entry->get_metadata();
520 507 $payment = $entry->get_payment_data();
521 508
522 509 if ( isset( $payment->payment_data ) && is_serialized( $payment->payment_data ) ) {
523 - // Security fix: Prevent PHP Object Injection by restricting allowed classes
524 - $payment->payment_data = @unserialize( $payment->payment_data, [ 'allowed_classes' => false ] );
510 + $payment->payment_data = unserialize( $payment->payment_data );
525 511 }
526 512
527 513 if ( false === $fields ) {
528 514 wp_send_json_error( __( 'No form fields found!', 'weforms' ) );
@@ -536,9 +522,9 @@
536 522
537 523 $has_empty = false;
538 524 $answers = [];
539 525 $respondentPoints = isset( $form_settings['total_points'] ) ? floatval( $form_settings['total_points'] ) : 0;
540 - $fields_formatted = array();
526 +
541 527 foreach ( $fields as $key => $field ) {
542 528 if ( $form_settings['quiz_form'] == 'yes' ) {
543 529 $selectedAnswers = isset( $field['selected_answers'] ) ? $field['selected_answers'] : '';
544 530 $givenAnswer = isset( $field['value'] ) ? $field['value'] : '';
@@ -547,8 +533,9 @@
547 533 $fieldPoints = isset( $field['points'] ) ? floatval( $field['points'] ) : 0;
548 534
549 535 if ( $template == 'radio_field' || $template == 'dropdown_field' ) {
550 536 $answers[$field['name']] = true;
537 +
551 538 if ( empty( $givenAnswer ) ) {
552 539 $answers[$field['name']] = false;
553 540 $respondentPoints -= $fieldPoints;
554 541 } else {
@@ -582,16 +569,14 @@
582 569 }
583 570 }
584 571 } elseif ( empty( $field['value'] ) ) {
585 572 $has_empty = true;
586 - continue;
587 - } else {
588 - $field = WeForms_Form_Entry_Manager::format_entry_value( $field );
589 - array_push( $fields_formatted, $field );
573 + break;
590 574 }
591 575 }
576 +
592 577 $response = [
593 - 'form_fields' => $fields_formatted,
578 + 'form_fields' => $fields,
594 579 'form_settings' => $form_settings,
595 580 'meta_data' => $metadata,
596 581 'payment_data' => $payment,
597 582 'has_empty' => $has_empty,
@@ -598,9 +583,8 @@
598 583 'respondent_points' => $respondentPoints,
599 584 'answers' => $answers,
600 585 ];
601 586
602 -
603 587 wp_send_json_success( $response );
604 588 }
605 589
606 590 /**
@@ -709,24 +693,13 @@
709 693 * @return void
710 694 */
711 695 public function handle_frontend_submission() {
712 696 check_ajax_referer( 'wpuf_form_add' );
697 +
713 698 $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
714 699 $page_id = isset( $_POST['page_id'] ) ? intval( $_POST['page_id'] ) : 0;
700 +
715 701 $form = weforms()->form->get( $form_id );
716 -
717 - /**
718 - * Check if form submission is open. This resolves broken access control with unauthenticated users.
719 - * Access is now checked on frontend form rendering and submission.
720 - */
721 - $form_submission_status = $form->is_submission_open();
722 - if ( is_wp_error( $form_submission_status ) ) {
723 - wp_send_json( [
724 - 'success' => false,
725 - 'error' => __( 'Login Required for submission.', 'weforms' ),
726 - ] );
727 - }
728 -
729 702 $form_settings = $form->get_settings();
730 703 $form_fields = $form->get_fields();
731 704 $entry_fields = $form->prepare_entries();
732 705 $form_entries = weforms_get_form_entries( $form_id, [ 'number' => '', 'offset' => '' ] );
@@ -780,40 +753,23 @@
780 753 $this->validate_submission( $entry_fields, $form, $form_settings, $form_fields );
781 754
782 755 $entry_fields = apply_filters( 'weforms_before_entry_submission', $entry_fields, $form, $form_settings, $form_fields );
783 756
784 - //check for entry_fields for a return error
785 - if ( is_wp_error( $entry_fields ) ) {
757 + $entry_id = weforms_insert_entry( [
758 + 'form_id' => $form_id,
759 + ], $entry_fields );
760 +
761 + if ( is_wp_error( $entry_id ) ) {
786 762 wp_send_json( [
787 763 'success' => false,
788 - 'error' => $entry_fields->get_error_message(),
764 + 'error' => $entry_id->get_error_message(),
789 765 ] );
790 - } else {
791 - $entry_id = 1;
792 - $global_settings = weforms_get_settings();
793 - if ( empty( $form_settings['after_submission'] ) ) {
794 - $entry_id = weforms_insert_entry( [
795 - 'form_id' => $form_id,
796 - ], $entry_fields );
797 - if ( is_wp_error( $entry_id ) ) {
798 - wp_send_json( [
799 - 'success' => false,
800 - 'error' => $entry_id->get_error_message(),
801 - ] );
802 - }
803 - // Fire a hook for integration
804 - do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
805 - $notification = new WeForms_Notification( [
806 - 'form_id' => $form_id,
807 - 'page_id' => $page_id,
808 - 'entry_id' => $entry_id,
809 - ] );
810 - $notification->send_notifications();
811 - }
812 766 }
767 +
813 768 // redirect URL
814 769 $show_message = false;
815 - $redirect_to = false;
770 + $redirect_to = false;
771 +
816 772 if ( $form_settings['redirect_to'] == 'page' ) {
817 773 $redirect_to = get_permalink( $form_settings['page_id'] );
818 774 } elseif ( $form_settings['redirect_to'] == 'url' ) {
819 775 $redirect_to = $form_settings['url'];
@@ -821,11 +777,17 @@
821 777 $show_message = true;
822 778 } else {
823 779 $show_message = true;
824 780 }
781 +
782 + // Fire a hook for integration
783 + do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
784 +
825 785 $field_search = $field_replace = [];
786 +
826 787 foreach ( $form_fields as $r_field ) {
827 788 $field_search[] = '{' . $r_field['name'] . '}';
789 +
828 790 if ( $r_field['template'] == 'name_field' ) {
829 791 $field_replace[] = implode( ' ', explode( '|', $entry_fields[ $r_field['name'] ] ) );
830 792 } else if ( $r_field['template'] == 'address_field' ) {
831 793 $field_replace[] = implode( ', ', $entry_fields[ $r_field['name'] ] );
@@ -833,60 +795,68 @@
833 795 $field_replace[] = isset( $entry_fields[ $r_field['name'] ] ) ? $entry_fields[ $r_field['name'] ] : '';
834 796 }
835 797 }
836 798 $message = str_replace( $field_search, $field_replace, $form_settings['message'] );
799 +
837 800 // send the response
838 801 $response = apply_filters( 'weforms_entry_submission_response', [
839 - 'success' => true,
840 - 'redirect_to' => $redirect_to,
802 + 'success' => true,
803 + 'redirect_to' => $redirect_to,
841 804 'show_message' => $show_message,
842 - 'message' => $message,
843 - 'data' => $_POST,
844 - 'form_id' => $form_id,
845 - 'entry_id' => $entry_id,
846 - 'entry_fields' =>$entry_fields,
805 + 'message' => $message,
806 + 'data' => $_POST,
807 + 'form_id' => $form_id,
808 + 'entry_id' => $entry_id,
847 809 ] );
848 810
811 + $notification = new WeForms_Notification( [
812 + 'form_id' => $form_id,
813 + 'page_id' => $page_id,
814 + 'entry_id' => $entry_id,
815 + ] );
816 +
817 + $notification->send_notifications();
818 +
849 819 weforms_clear_buffer();
850 820 wp_send_json( $response );
851 - }
821 + }
852 822
853 - function validate_reCaptchav3( $secret ) {
854 - check_ajax_referer( 'wpuf_form_add' );
823 + function validate_reCaptchav3( $secret ) {
824 + check_ajax_referer( 'wpuf_form_add' );
855 825
856 - $post_data = wp_unslash($_POST);
857 - $token = $post_data['g-recaptcha-response'];
858 - $action = $post_data['g-action'];
859 - $google_captcha_url = esc_url( 'https://www.google.com/recaptcha/api/siteverify' );
826 + $post_data = wp_unslash($_POST);
827 + $token = $post_data['g-recaptcha-response'];
828 + $action = $post_data['g-action'];
829 + $google_captcha_url = esc_url( 'https://www.google.com/recaptcha/api/siteverify' );
860 830
861 - $response = wp_remote_post( $google_captcha_url,
862 - array(
863 - 'method' => 'POST',
864 - 'body' => array(
865 - 'secret' => $secret,
866 - 'response' => $token
867 - )
831 + $response = wp_remote_post( $google_captcha_url,
832 + array(
833 + 'method' => 'POST',
834 + 'body' => array(
835 + 'secret' => $secret,
836 + 'response' => $token
868 837 )
869 - );
838 + )
839 + );
870 840
871 841
872 - if ( is_wp_error( $response ) ) {
842 + if ( is_wp_error( $response ) ) {
843 + wp_send_json( [
844 + 'success' => false,
845 + 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
846 + ] );
847 + } else {
848 + $api_response = json_decode( wp_remote_retrieve_body( $response ), true );
849 + if( $api_response["success"] == '1' && $api_response["action"] == $action ) {
850 + return true;
851 + } else {
873 852 wp_send_json( [
874 853 'success' => false,
875 854 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
876 855 ] );
877 - } else {
878 - $api_response = json_decode( wp_remote_retrieve_body( $response ), true );
879 - if( $api_response["success"] == '1' && $api_response["action"] == $action ) {
880 - return true;
881 - } else {
882 - wp_send_json( [
883 - 'success' => false,
884 - 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
885 - ] );
886 - }
887 856 }
888 857 }
858 + }
889 859 /**
890 860 * reCaptcha Validation
891 861 *
892 862 * @return void