Commit Graph

4807 Commits

Author SHA1 Message Date
Mykyta Synelnikov 5633531153 Merge pull request #1643 from ultimatemember/fix/privacy_policy
Fix the "Privacy Policy" field in the registration form (CU-86cxva4f0)
2025-02-12 17:49:56 +02:00
Mykyta Synelnikov 422d2b7c67 Refactor password handling to bypass wp_unslash.
Introduce a dedicated method to handle password fields securely, avoiding `wp_unslash` for these fields. This enhances consistency and security when processing form data across the plugin.
2025-02-12 17:47:19 +02:00
Mykyta Synelnikov cbc8c24b35 Merge pull request #1647 from ultimatemember/fix/password
Password set in Dashboard can't be used for UM login or vice versa (CU-86cxwy7ww)
2025-02-12 17:21:27 +02:00
Mykyta Synelnikov 38593400ba Merge pull request #1644 from ultimatemember/fix/updates-request
Fixes updates request
2025-02-12 17:16:56 +02:00
Mykyta Synelnikov 51c4d6f072 Merge pull request #1645 from ultimatemember/security/mysql
Fixes CVE-2024-12276
2025-02-12 17:15:23 +02:00
yuriinalivaiko 17d95a189b Task CU-86cxwy7ww
- password sanitize has been changed to the standard WordPress one.
2025-02-04 23:23:26 +02:00
Mykyta Synelnikov 4adbe19cbe * fixed CVE-2024-12276;
* reviewed using $wpdb and WPCS;
* set minimum required version to 6.2 due to using %i for $wpdb->prepare;
2025-02-03 16:17:37 +02:00
Mykyta Synelnikov a760a6242e * updated requests to site URL;
* WPCS;
2025-01-31 15:19:28 +02:00
yuriinalivaiko 0221b40b57 Task CU-86cxva4f0
- fixed the "Privacy Policy" field in the registration form - stripped out forms and other disallowed HTML from the "Privacy Policy" content.
2025-01-30 23:21:29 +02:00
Mykyta Synelnikov 26c8aa21e1 Merge pull request #1642 from ultimatemember/fix/honeypot_script_style
Fixes honeypot script&style
2025-01-30 13:04:30 +02:00
Mykyta Synelnikov 865fbf83c2 * added honeypot scripts/styles via
`wp_add_inline_script()`, `wp_add_inline_style()`
2025-01-30 13:00:17 +02:00
Mykyta Synelnikov 4d43d94502 * related to https://github.com/ultimatemember/ultimatemember/commit/8ca44d02a02e887fc4ab9bcb8ea9ff18ab2c0413 2025-01-30 12:33:49 +02:00
Mykyta Synelnikov 236293645a Merge pull request #1641 from ultimatemember/fix/cover_profile_photo_on_view
Cover and Profile photo uploaders (CU-86cxtae21) alternativity
2025-01-29 16:48:50 +02:00
Mykyta Synelnikov bb0a49e08a * update dropdown items texts on cover photo change/remove;
* WPCS;
2025-01-29 16:44:29 +02:00
Mykyta Synelnikov fce490f54b * update dropdown items texts on cover photo change/remove;
* WPCS;
2025-01-29 16:43:05 +02:00
Mykyta Synelnikov 4dd1be344e * backward compatibility;
* update dropdown items texts on profile photo change/remove;
* added escapers;
* WPCS;
2025-01-29 16:01:02 +02:00
Mykyta Synelnikov 0520a55cc4 * removed hidden inputs on view mode;
* handle data attribute instead of the hidden input;
* WPCS;
2025-01-29 14:49:47 +02:00
Mykyta Synelnikov e9e68e28cf * added data attribute;
* updated hooks docs;
* WPCS;
2025-01-29 14:24:15 +02:00
Mykyta Synelnikov 817bc4b2e3 * fixed #1636 2025-01-24 18:32:11 +02:00
Mykyta Synelnikov 0e2cd16f73 Merge pull request #1634 from ultimatemember/fix/og_image_size
Open Graph Image Size (CU-86cxq9tuk)
2025-01-24 18:20:41 +02:00
Mykyta Synelnikov 5fc2cd54a4 * Reviewed #1634 2025-01-24 18:19:14 +02:00
yuriinalivaiko 5952c06c59 Task CU-86cxq9tuk
- changed Open Graph image size.
2025-01-19 14:58:59 +02:00
yuriinalivaiko 8bf8a0130b fixed "Download your data" and "Erase of your data" fields layout. 2025-01-17 16:03:51 +02:00
Mykyta Synelnikov b0b9f82ebe * fixed order_count meta table update 2025-01-15 12:02:08 +02:00
Mykyta Synelnikov 0624a634d2 * fixed money_spent meta table update 2025-01-14 17:36:20 +02:00
Mykyta Synelnikov 6aab8152f8 * bump version; 2025-01-14 17:21:26 +02:00
WordPress .pot File Generator 0d490d7d3a 🔄 Generated POT File 2025-01-14 13:51:46 +00:00
Mykyta Synelnikov c1171d51b2 * fixed #1626; 2025-01-14 15:51:21 +02:00
WordPress .pot File Generator 2cc2885757 🔄 Generated POT File 2025-01-14 13:42:27 +00:00
Mykyta Synelnikov e72b5bdf75 Merge pull request #1610 from ultimatemember/development/2.9.x
Version 2.9.2 - 2025 year patch
2025-01-14 15:42:05 +02:00
Mykyta Synelnikov 980de8a800 Merge branch 'master' into development/2.9.x 2025-01-14 15:40:11 +02:00
Mykyta Synelnikov 5cb6ae6dc5 * prepared to the release 2025-01-14 15:39:01 +02:00
Mykyta Synelnikov 5b2c785def * prepared to the release 2025-01-14 15:28:28 +02:00
Mykyta Synelnikov f7b3585b1a * prepared to the release 2025-01-14 15:24:45 +02:00
Mykyta Synelnikov 27aeef42af * prepared to the release 2025-01-14 15:24:03 +02:00
Mykyta Synelnikov dc81fa44ae Merge pull request #1607 from ultimatemember/fix/remove_mobile_detect
Deprecates mobile detect library
2025-01-14 12:02:23 +02:00
Mykyta Synelnikov fa0cfa84c2 Merge pull request #1616 from ultimatemember/fix/md_security
Fixes security vulnerabilities
2025-01-14 11:55:43 +02:00
Mykyta Synelnikov 5ebefde6b8 * fixed security issue CVE ID: CVE-2025-0308 2025-01-10 02:17:18 +02:00
Mykyta Synelnikov e5fe05503a * fixed security issue CVE ID: CVE-2025-0308
* fixed security issue CVE ID: CVE-2025-0318
2025-01-08 12:20:35 +02:00
Mykyta Synelnikov 5cefd5ba3a Merge pull request #1609 from ultimatemember/fix/cropper-scalable
Maybe cropper.js fix
2025-01-02 14:10:04 +02:00
Mykyta Synelnikov 3c88512bc2 Merge pull request #1608 from ultimatemember/fix/show-hide-pw-ms-browser
Fixes show/hide password buttion in Edge browser
2024-12-20 01:03:20 +02:00
Mykyta Synelnikov a0892e18aa * enhancements related to #1599; 2024-12-19 17:24:52 +02:00
Mykyta Synelnikov 9d45a9f088 * fixed scalable attribute for cropper; 2024-12-19 13:25:29 +02:00
Mykyta Synelnikov 44bfcdeb38 * removed ms-native show password button for type="password" field in UM forms; 2024-12-19 13:00:20 +02:00
WordPress .pot File Generator 7bccbac786 🔄 Generated POT File 2024-12-19 10:48:27 +00:00
Mykyta Synelnikov 6ae63cfc93 * updated "woocommerce/action-scheduler" to 3.9.0 2024-12-19 12:48:00 +02:00
Mykyta Synelnikov 1ba3809344 * using wp_is_mobile instead of MobileDetect library 2024-12-17 21:53:18 +02:00
Mykyta Synelnikov a6904639f3 Merge pull request #1604 from ultimatemember/feature/submitted_registration_data
Submitted registration data
2024-12-17 16:11:35 +02:00
ashubawork 6653769d72 - add a hooks for submitted registration data 2024-12-17 15:48:20 +02:00
WordPress .pot File Generator 447242e93a 🔄 Generated POT File 2024-12-16 20:24:53 +00:00