PluginProbe
weForms – Easy Drag & Drop Contact Form Builder For WordPress / 1.6.1
weForms – Easy Drag & Drop Contact Form Builder For WordPress v1.6.1
1.6.7 1.6.8 1.6.9 1.6.12 1.6.13 1.6.14 1.6.15 1.6.16 1.6.17 1.6.18 1.6.19 1.6.2 1.6.20 1.6.21 1.6.22 1.6.23 1.6.24 1.6.25 1.6.26 1.6.27 1.6.28 1.6.3 1.6.4 1.6.5 1.6.6 All 74 releases
← All changes | includes/class-ajax.php +68 -95 1.6.211.6.1 View file →
@@ -108,12 +108,9 @@
108 108 $settings = array();
109 109 $integrations = array();
110 110
111 111 if ( isset( $post_data['settings'] ) ) {
112 - $settings = json_decode( $post_data['settings'], true );
113 - $settings['message'] = sanitize_text_field( $settings['message'] );
114 - $settings['url'] = sanitize_url( $settings['url'] );
115 - $settings['limit_message'] = sanitize_text_field( $settings['limit_message'] );
112 + $settings = (array) json_decode( $post_data['settings'] );
116 113 } else {
117 114 $settings = isset( $form_data['wpuf_settings'] ) ? $form_data['wpuf_settings'] : [];
118 115 }
119 116
@@ -120,8 +117,11 @@
120 117 if ( isset( $post_data['integrations'] ) ) {
121 118 $integrations = (array) json_decode( $post_data['integrations'] );
122 119 }
123 120
121 + // $form_fields = wp_unslash( $form_fields );
122 + // $notifications = wp_unslash( $notifications );
123 +
124 124 $form_fields = json_decode( $form_fields, true );
125 125 $notifications = json_decode( $notifications, true );
126 126 $data = [
127 127 'form_id' => absint( $form_data['wpuf_form_id'] ),
@@ -134,22 +134,11 @@
134 134 ];
135 135
136 136 $form_fields = weforms()->form->save( $data );
137 137
138 - // Update Old Entry meta_key if changed
139 - $form_id = $form_data['wpuf_form_id'];
140 - $form = weforms()->form->get( $form_id );
141 -
142 - $form->maybe_update_entries( $form_fields );
143 -
144 138 do_action( 'weforms_update_form', $form_data['wpuf_form_id'], $form_fields, $settings );
145 139
146 - wp_send_json_success(
147 - array(
148 - 'form_fields' => $form_fields,
149 - 'settings' => $settings,
150 - )
151 - );
140 + wp_send_json_success( [ 'form_fields' => $form_fields ] );
152 141 }
153 142
154 143 /**
155 144 * Get all contact forms
@@ -535,9 +524,9 @@
535 524
536 525 $has_empty = false;
537 526 $answers = [];
538 527 $respondentPoints = isset( $form_settings['total_points'] ) ? floatval( $form_settings['total_points'] ) : 0;
539 - $fields_formatted = array();
528 +
540 529 foreach ( $fields as $key => $field ) {
541 530 if ( $form_settings['quiz_form'] == 'yes' ) {
542 531 $selectedAnswers = isset( $field['selected_answers'] ) ? $field['selected_answers'] : '';
543 532 $givenAnswer = isset( $field['value'] ) ? $field['value'] : '';
@@ -546,8 +535,9 @@
546 535 $fieldPoints = isset( $field['points'] ) ? floatval( $field['points'] ) : 0;
547 536
548 537 if ( $template == 'radio_field' || $template == 'dropdown_field' ) {
549 538 $answers[$field['name']] = true;
539 +
550 540 if ( empty( $givenAnswer ) ) {
551 541 $answers[$field['name']] = false;
552 542 $respondentPoints -= $fieldPoints;
553 543 } else {
@@ -581,16 +571,14 @@
581 571 }
582 572 }
583 573 } elseif ( empty( $field['value'] ) ) {
584 574 $has_empty = true;
585 - continue;
586 - } else {
587 - $field = WeForms_Form_Entry_Manager::format_entry_value( $field );
588 - array_push( $fields_formatted, $field );
575 + break;
589 576 }
590 577 }
578 +
591 579 $response = [
592 - 'form_fields' => $fields_formatted,
580 + 'form_fields' => $fields,
593 581 'form_settings' => $form_settings,
594 582 'meta_data' => $metadata,
595 583 'payment_data' => $payment,
596 584 'has_empty' => $has_empty,
@@ -597,9 +585,8 @@
597 585 'respondent_points' => $respondentPoints,
598 586 'answers' => $answers,
599 587 ];
600 588
601 -
602 589 wp_send_json_success( $response );
603 590 }
604 591
605 592 /**
@@ -708,24 +695,13 @@
708 695 * @return void
709 696 */
710 697 public function handle_frontend_submission() {
711 698 check_ajax_referer( 'wpuf_form_add' );
699 +
712 700 $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
713 701 $page_id = isset( $_POST['page_id'] ) ? intval( $_POST['page_id'] ) : 0;
702 +
714 703 $form = weforms()->form->get( $form_id );
715 -
716 - /**
717 - * Check if form submission is open. This resolves broken access control with unauthenticated users.
718 - * Access is now checked on frontend form rendering and submission.
719 - */
720 - $form_submission_status = $form->is_submission_open();
721 - if ( is_wp_error( $form_submission_status ) ) {
722 - wp_send_json( [
723 - 'success' => false,
724 - 'error' => __( 'Login Required for submission.', 'weforms' ),
725 - ] );
726 - }
727 -
728 704 $form_settings = $form->get_settings();
729 705 $form_fields = $form->get_fields();
730 706 $entry_fields = $form->prepare_entries();
731 707 $form_entries = weforms_get_form_entries( $form_id, [ 'number' => '', 'offset' => '' ] );
@@ -779,40 +755,23 @@
779 755 $this->validate_submission( $entry_fields, $form, $form_settings, $form_fields );
780 756
781 757 $entry_fields = apply_filters( 'weforms_before_entry_submission', $entry_fields, $form, $form_settings, $form_fields );
782 758
783 - //check for entry_fields for a return error
784 - if ( is_wp_error( $entry_fields ) ) {
759 + $entry_id = weforms_insert_entry( [
760 + 'form_id' => $form_id,
761 + ], $entry_fields );
762 +
763 + if ( is_wp_error( $entry_id ) ) {
785 764 wp_send_json( [
786 765 'success' => false,
787 - 'error' => $entry_fields->get_error_message(),
766 + 'error' => $entry_id->get_error_message(),
788 767 ] );
789 - } else {
790 - $entry_id = 1;
791 - $global_settings = weforms_get_settings();
792 - if ( empty( $form_settings['after_submission'] ) ) {
793 - $entry_id = weforms_insert_entry( [
794 - 'form_id' => $form_id,
795 - ], $entry_fields );
796 - if ( is_wp_error( $entry_id ) ) {
797 - wp_send_json( [
798 - 'success' => false,
799 - 'error' => $entry_id->get_error_message(),
800 - ] );
801 - }
802 - // Fire a hook for integration
803 - do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
804 - $notification = new WeForms_Notification( [
805 - 'form_id' => $form_id,
806 - 'page_id' => $page_id,
807 - 'entry_id' => $entry_id,
808 - ] );
809 - $notification->send_notifications();
810 - }
811 768 }
769 +
812 770 // redirect URL
813 771 $show_message = false;
814 - $redirect_to = false;
772 + $redirect_to = false;
773 +
815 774 if ( $form_settings['redirect_to'] == 'page' ) {
816 775 $redirect_to = get_permalink( $form_settings['page_id'] );
817 776 } elseif ( $form_settings['redirect_to'] == 'url' ) {
818 777 $redirect_to = $form_settings['url'];
@@ -820,11 +779,17 @@
820 779 $show_message = true;
821 780 } else {
822 781 $show_message = true;
823 782 }
783 +
784 + // Fire a hook for integration
785 + do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
786 +
824 787 $field_search = $field_replace = [];
788 +
825 789 foreach ( $form_fields as $r_field ) {
826 790 $field_search[] = '{' . $r_field['name'] . '}';
791 +
827 792 if ( $r_field['template'] == 'name_field' ) {
828 793 $field_replace[] = implode( ' ', explode( '|', $entry_fields[ $r_field['name'] ] ) );
829 794 } else if ( $r_field['template'] == 'address_field' ) {
830 795 $field_replace[] = implode( ', ', $entry_fields[ $r_field['name'] ] );
@@ -832,60 +797,68 @@
832 797 $field_replace[] = isset( $entry_fields[ $r_field['name'] ] ) ? $entry_fields[ $r_field['name'] ] : '';
833 798 }
834 799 }
835 800 $message = str_replace( $field_search, $field_replace, $form_settings['message'] );
801 +
836 802 // send the response
837 803 $response = apply_filters( 'weforms_entry_submission_response', [
838 - 'success' => true,
839 - 'redirect_to' => $redirect_to,
804 + 'success' => true,
805 + 'redirect_to' => $redirect_to,
840 806 'show_message' => $show_message,
841 - 'message' => $message,
842 - 'data' => $_POST,
843 - 'form_id' => $form_id,
844 - 'entry_id' => $entry_id,
845 - 'entry_fields' =>$entry_fields,
807 + 'message' => $message,
808 + 'data' => $_POST,
809 + 'form_id' => $form_id,
810 + 'entry_id' => $entry_id,
846 811 ] );
847 812
813 + $notification = new WeForms_Notification( [
814 + 'form_id' => $form_id,
815 + 'page_id' => $page_id,
816 + 'entry_id' => $entry_id,
817 + ] );
818 +
819 + $notification->send_notifications();
820 +
848 821 weforms_clear_buffer();
849 822 wp_send_json( $response );
850 - }
823 + }
851 824
852 - function validate_reCaptchav3( $secret ) {
853 - check_ajax_referer( 'wpuf_form_add' );
825 + function validate_reCaptchav3( $secret ) {
826 + check_ajax_referer( 'wpuf_form_add' );
854 827
855 - $post_data = wp_unslash($_POST);
856 - $token = $post_data['g-recaptcha-response'];
857 - $action = $post_data['g-action'];
858 - $google_captcha_url = esc_url( 'https://www.google.com/recaptcha/api/siteverify' );
828 + $post_data = wp_unslash($_POST);
829 + $token = $post_data['g-recaptcha-response'];
830 + $action = $post_data['g-action'];
831 + $google_captcha_url = esc_url( 'https://www.google.com/recaptcha/api/siteverify' );
859 832
860 - $response = wp_remote_post( $google_captcha_url,
861 - array(
862 - 'method' => 'POST',
863 - 'body' => array(
864 - 'secret' => $secret,
865 - 'response' => $token
866 - )
833 + $response = wp_remote_post( $google_captcha_url,
834 + array(
835 + 'method' => 'POST',
836 + 'body' => array(
837 + 'secret' => $secret,
838 + 'response' => $token
867 839 )
868 - );
840 + )
841 + );
869 842
870 843
871 - if ( is_wp_error( $response ) ) {
844 + if ( is_wp_error( $response ) ) {
845 + wp_send_json( [
846 + 'success' => false,
847 + 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
848 + ] );
849 + } else {
850 + $api_response = json_decode( wp_remote_retrieve_body( $response ), true );
851 + if( $api_response["success"] == '1' && $api_response["action"] == $action ) {
852 + return true;
853 + } else {
872 854 wp_send_json( [
873 855 'success' => false,
874 856 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
875 857 ] );
876 - } else {
877 - $api_response = json_decode( wp_remote_retrieve_body( $response ), true );
878 - if( $api_response["success"] == '1' && $api_response["action"] == $action ) {
879 - return true;
880 - } else {
881 - wp_send_json( [
882 - 'success' => false,
883 - 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
884 - ] );
885 - }
886 858 }
887 859 }
860 + }
888 861 /**
889 862 * reCaptcha Validation
890 863 *
891 864 * @return void