PluginProbe
weForms – Easy Drag & Drop Contact Form Builder For WordPress / 1.6.11
weForms – Easy Drag & Drop Contact Form Builder For WordPress v1.6.11
1.6.7 1.6.8 1.6.9 1.6.12 1.6.13 1.6.14 1.6.15 1.6.16 1.6.17 1.6.18 1.6.19 1.6.2 1.6.20 1.6.21 1.6.22 1.6.23 1.6.24 1.6.25 1.6.26 1.6.27 1.6.28 1.6.3 1.6.4 1.6.5 1.6.6 All 74 releases
← All changes | includes/class-ajax.php +24 -53 1.6.281.6.11 View file →
@@ -108,12 +108,9 @@
108 108 $settings = array();
109 109 $integrations = array();
110 110
111 111 if ( isset( $post_data['settings'] ) ) {
112 - $settings = json_decode( $post_data['settings'], true );
113 - $settings['message'] = sanitize_text_field( $settings['message'] );
114 - $settings['url'] = sanitize_url( $settings['url'] );
115 - $settings['limit_message'] = sanitize_text_field( $settings['limit_message'] );
112 + $settings = (array) json_decode( $post_data['settings'] );
116 113 } else {
117 114 $settings = isset( $form_data['wpuf_settings'] ) ? $form_data['wpuf_settings'] : [];
118 115 }
119 116
@@ -142,14 +139,9 @@
142 139 $form->maybe_update_entries( $form_fields );
143 140
144 141 do_action( 'weforms_update_form', $form_data['wpuf_form_id'], $form_fields, $settings );
145 142
146 - wp_send_json_success(
147 - array(
148 - 'form_fields' => $form_fields,
149 - 'settings' => $settings,
150 - )
151 - );
143 + wp_send_json_success( [ 'form_fields' => $form_fields ] );
152 144 }
153 145
154 146 /**
155 147 * Get all contact forms
@@ -519,10 +511,9 @@
519 511 $metadata = $entry->get_metadata();
520 512 $payment = $entry->get_payment_data();
521 513
522 514 if ( isset( $payment->payment_data ) && is_serialized( $payment->payment_data ) ) {
523 - // Security fix: Prevent PHP Object Injection by restricting allowed classes
524 - $payment->payment_data = @unserialize( $payment->payment_data, [ 'allowed_classes' => false ] );
515 + $payment->payment_data = unserialize( $payment->payment_data );
525 516 }
526 517
527 518 if ( false === $fields ) {
528 519 wp_send_json_error( __( 'No form fields found!', 'weforms' ) );
@@ -582,9 +573,9 @@
582 573 }
583 574 }
584 575 } elseif ( empty( $field['value'] ) ) {
585 576 $has_empty = true;
586 - continue;
577 + break;
587 578 } else {
588 579 $field = WeForms_Form_Entry_Manager::format_entry_value( $field );
589 580 array_push( $fields_formatted, $field );
590 581 }
@@ -709,24 +700,13 @@
709 700 * @return void
710 701 */
711 702 public function handle_frontend_submission() {
712 703 check_ajax_referer( 'wpuf_form_add' );
704 +
713 705 $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
714 706 $page_id = isset( $_POST['page_id'] ) ? intval( $_POST['page_id'] ) : 0;
707 +
715 708 $form = weforms()->form->get( $form_id );
716 -
717 - /**
718 - * Check if form submission is open. This resolves broken access control with unauthenticated users.
719 - * Access is now checked on frontend form rendering and submission.
720 - */
721 - $form_submission_status = $form->is_submission_open();
722 - if ( is_wp_error( $form_submission_status ) ) {
723 - wp_send_json( [
724 - 'success' => false,
725 - 'error' => __( 'Login Required for submission.', 'weforms' ),
726 - ] );
727 - }
728 -
729 709 $form_settings = $form->get_settings();
730 710 $form_fields = $form->get_fields();
731 711 $entry_fields = $form->prepare_entries();
732 712 $form_entries = weforms_get_form_entries( $form_id, [ 'number' => '', 'offset' => '' ] );
@@ -780,36 +760,28 @@
780 760 $this->validate_submission( $entry_fields, $form, $form_settings, $form_fields );
781 761
782 762 $entry_fields = apply_filters( 'weforms_before_entry_submission', $entry_fields, $form, $form_settings, $form_fields );
783 763
784 - //check for entry_fields for a return error
785 - if ( is_wp_error( $entry_fields ) ) {
786 - wp_send_json( [
787 - 'success' => false,
788 - 'error' => $entry_fields->get_error_message(),
789 - ] );
790 - } else {
791 - $entry_id = 1;
792 - $global_settings = weforms_get_settings();
793 - if ( empty( $form_settings['after_submission'] ) ) {
794 - $entry_id = weforms_insert_entry( [
795 - 'form_id' => $form_id,
796 - ], $entry_fields );
797 - if ( is_wp_error( $entry_id ) ) {
798 - wp_send_json( [
799 - 'success' => false,
800 - 'error' => $entry_id->get_error_message(),
801 - ] );
802 - }
803 - // Fire a hook for integration
804 - do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
805 - $notification = new WeForms_Notification( [
806 - 'form_id' => $form_id,
807 - 'page_id' => $page_id,
808 - 'entry_id' => $entry_id,
764 + $entry_id = 1;
765 + $global_settings = weforms_get_settings();
766 + if ( empty( $form_settings['after_submission'] ) ) {
767 + $entry_id = weforms_insert_entry( [
768 + 'form_id' => $form_id,
769 + ], $entry_fields );
770 + if ( is_wp_error( $entry_id ) ) {
771 + wp_send_json( [
772 + 'success' => false,
773 + 'error' => $entry_id->get_error_message(),
809 774 ] );
810 - $notification->send_notifications();
811 775 }
776 + // Fire a hook for integration
777 + do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
778 + $notification = new WeForms_Notification( [
779 + 'form_id' => $form_id,
780 + 'page_id' => $page_id,
781 + 'entry_id' => $entry_id,
782 + ] );
783 + $notification->send_notifications();
812 784 }
813 785 // redirect URL
814 786 $show_message = false;
815 787 $redirect_to = false;
@@ -844,9 +816,8 @@
844 816 'form_id' => $form_id,
845 817 'entry_id' => $entry_id,
846 818 'entry_fields' =>$entry_fields,
847 819 ] );
848 -
849 820 weforms_clear_buffer();
850 821 wp_send_json( $response );
851 822 }
852 823