PluginProbe
weForms – Easy Drag & Drop Contact Form Builder For WordPress / 1.6.9
weForms – Easy Drag & Drop Contact Form Builder For WordPress v1.6.9
1.6.7 1.6.8 1.6.9 1.6.12 1.6.13 1.6.14 1.6.15 1.6.16 1.6.17 1.6.18 1.6.19 1.6.2 1.6.20 1.6.21 1.6.22 1.6.23 1.6.24 1.6.25 1.6.26 1.6.27 1.6.28 1.6.3 1.6.4 1.6.5 1.6.6 All 74 releases
← All changes | includes/class-ajax.php +28 -59 1.6.271.6.9 View file →
@@ -108,12 +108,9 @@
108 108 $settings = array();
109 109 $integrations = array();
110 110
111 111 if ( isset( $post_data['settings'] ) ) {
112 - $settings = json_decode( $post_data['settings'], true );
113 - $settings['message'] = sanitize_text_field( $settings['message'] );
114 - $settings['url'] = sanitize_url( $settings['url'] );
115 - $settings['limit_message'] = sanitize_text_field( $settings['limit_message'] );
112 + $settings = (array) json_decode( $post_data['settings'] );
116 113 } else {
117 114 $settings = isset( $form_data['wpuf_settings'] ) ? $form_data['wpuf_settings'] : [];
118 115 }
119 116
@@ -137,19 +134,14 @@
137 134
138 135 // Update Old Entry meta_key if changed
139 136 $form_id = $form_data['wpuf_form_id'];
140 137 $form = weforms()->form->get( $form_id );
141 -
138 +
142 139 $form->maybe_update_entries( $form_fields );
143 140
144 141 do_action( 'weforms_update_form', $form_data['wpuf_form_id'], $form_fields, $settings );
145 142
146 - wp_send_json_success(
147 - array(
148 - 'form_fields' => $form_fields,
149 - 'settings' => $settings,
150 - )
151 - );
143 + wp_send_json_success( [ 'form_fields' => $form_fields ] );
152 144 }
153 145
154 146 /**
155 147 * Get all contact forms
@@ -519,10 +511,9 @@
519 511 $metadata = $entry->get_metadata();
520 512 $payment = $entry->get_payment_data();
521 513
522 514 if ( isset( $payment->payment_data ) && is_serialized( $payment->payment_data ) ) {
523 - // Security fix: Prevent PHP Object Injection by restricting allowed classes
524 - $payment->payment_data = @unserialize( $payment->payment_data, [ 'allowed_classes' => false ] );
515 + $payment->payment_data = unserialize( $payment->payment_data );
525 516 }
526 517
527 518 if ( false === $fields ) {
528 519 wp_send_json_error( __( 'No form fields found!', 'weforms' ) );
@@ -536,9 +527,9 @@
536 527
537 528 $has_empty = false;
538 529 $answers = [];
539 530 $respondentPoints = isset( $form_settings['total_points'] ) ? floatval( $form_settings['total_points'] ) : 0;
540 - $fields_formatted = array();
531 +
541 532 foreach ( $fields as $key => $field ) {
542 533 if ( $form_settings['quiz_form'] == 'yes' ) {
543 534 $selectedAnswers = isset( $field['selected_answers'] ) ? $field['selected_answers'] : '';
544 535 $givenAnswer = isset( $field['value'] ) ? $field['value'] : '';
@@ -547,8 +538,9 @@
547 538 $fieldPoints = isset( $field['points'] ) ? floatval( $field['points'] ) : 0;
548 539
549 540 if ( $template == 'radio_field' || $template == 'dropdown_field' ) {
550 541 $answers[$field['name']] = true;
542 +
551 543 if ( empty( $givenAnswer ) ) {
552 544 $answers[$field['name']] = false;
553 545 $respondentPoints -= $fieldPoints;
554 546 } else {
@@ -582,16 +574,14 @@
582 574 }
583 575 }
584 576 } elseif ( empty( $field['value'] ) ) {
585 577 $has_empty = true;
586 - continue;
587 - } else {
588 - $field = WeForms_Form_Entry_Manager::format_entry_value( $field );
589 - array_push( $fields_formatted, $field );
578 + break;
590 579 }
591 580 }
581 +
592 582 $response = [
593 - 'form_fields' => $fields_formatted,
583 + 'form_fields' => $fields,
594 584 'form_settings' => $form_settings,
595 585 'meta_data' => $metadata,
596 586 'payment_data' => $payment,
597 587 'has_empty' => $has_empty,
@@ -598,9 +588,8 @@
598 588 'respondent_points' => $respondentPoints,
599 589 'answers' => $answers,
600 590 ];
601 591
602 -
603 592 wp_send_json_success( $response );
604 593 }
605 594
606 595 /**
@@ -709,24 +698,13 @@
709 698 * @return void
710 699 */
711 700 public function handle_frontend_submission() {
712 701 check_ajax_referer( 'wpuf_form_add' );
702 +
713 703 $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
714 704 $page_id = isset( $_POST['page_id'] ) ? intval( $_POST['page_id'] ) : 0;
705 +
715 706 $form = weforms()->form->get( $form_id );
716 -
717 - /**
718 - * Check if form submission is open. This resolves broken access control with unauthenticated users.
719 - * Access is now checked on frontend form rendering and submission.
720 - */
721 - $form_submission_status = $form->is_submission_open();
722 - if ( is_wp_error( $form_submission_status ) ) {
723 - wp_send_json( [
724 - 'success' => false,
725 - 'error' => __( 'Login Required for submission.', 'weforms' ),
726 - ] );
727 - }
728 -
729 707 $form_settings = $form->get_settings();
730 708 $form_fields = $form->get_fields();
731 709 $entry_fields = $form->prepare_entries();
732 710 $form_entries = weforms_get_form_entries( $form_id, [ 'number' => '', 'offset' => '' ] );
@@ -780,37 +758,29 @@
780 758 $this->validate_submission( $entry_fields, $form, $form_settings, $form_fields );
781 759
782 760 $entry_fields = apply_filters( 'weforms_before_entry_submission', $entry_fields, $form, $form_settings, $form_fields );
783 761
784 - //check for entry_fields for a return error
785 - if ( is_wp_error( $entry_fields ) ) {
762 + $entry_id = 1;
763 + $global_settings = weforms_get_settings();
764 + if ( empty( $global_settings['after_submission'] ) ) {
765 + $entry_id = weforms_insert_entry( [
766 + 'form_id' => $form_id,
767 + ], $entry_fields );
768 + if ( is_wp_error( $entry_id ) ) {
786 769 wp_send_json( [
787 770 'success' => false,
788 - 'error' => $entry_fields->get_error_message(),
771 + 'error' => $entry_id->get_error_message(),
789 772 ] );
790 - } else {
791 - $entry_id = 1;
792 - $global_settings = weforms_get_settings();
793 - if ( empty( $form_settings['after_submission'] ) ) {
794 - $entry_id = weforms_insert_entry( [
795 - 'form_id' => $form_id,
796 - ], $entry_fields );
797 - if ( is_wp_error( $entry_id ) ) {
798 - wp_send_json( [
799 - 'success' => false,
800 - 'error' => $entry_id->get_error_message(),
801 - ] );
802 - }
803 - // Fire a hook for integration
804 - do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
805 - $notification = new WeForms_Notification( [
806 - 'form_id' => $form_id,
807 - 'page_id' => $page_id,
808 - 'entry_id' => $entry_id,
809 - ] );
810 - $notification->send_notifications();
811 - }
812 773 }
774 + // Fire a hook for integration
775 + do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
776 + $notification = new WeForms_Notification( [
777 + 'form_id' => $form_id,
778 + 'page_id' => $page_id,
779 + 'entry_id' => $entry_id,
780 + ] );
781 + $notification->send_notifications();
782 + }
813 783 // redirect URL
814 784 $show_message = false;
815 785 $redirect_to = false;
816 786 if ( $form_settings['redirect_to'] == 'page' ) {
@@ -844,9 +814,8 @@
844 814 'form_id' => $form_id,
845 815 'entry_id' => $entry_id,
846 816 'entry_fields' =>$entry_fields,
847 817 ] );
848 -
849 818 weforms_clear_buffer();
850 819 wp_send_json( $response );
851 820 }
852 821