Skip to content

Fix: Form Entries - #1210

Draft
n7studios wants to merge 1 commit into
mainfrom
fix-form-entries
Draft

n7studios wants to merge 1 commit into
mainfrom
fix-form-entries

Conversation

@n7studios

Copy link
Copy Markdown
Contributor

Summary

Fixes several issues with Form Entries (Settings > Kit > Form Entries), and the ConvertKit_Form_Entries class:

  • Table not created on WordPress 5.6 – 6.1. Queries used the %i identifier placeholder, which $wpdb->prepare() only supports from WordPress 6.2. The Plugin requires WordPress 5.6, so on older versions the CREATE TABLE query failed and Form Builder entries were never stored. The 3.0.4 upgrade routine that adds the form_id column had the same issue. The table name is now interpolated from $wpdb->prefix instead, matching get_by_ids() and delete_by_ids().
  • CSV export broke with custom fields, quotes or commas. Values weren't escaped, so custom fields (stored as JSON) or any value containing a double quote corrupted the row. Double quotes are now escaped.
  • CSV formula injection. Entries are submitted by site visitors, and values starting with =, +, -, @, tab or carriage return were exported as-is, so spreadsheet applications would run them as formulas. These values are now prefixed with ' so they're treated as text.
  • update() returned the wrong ID. It returned $wpdb->insert_id (0, or the last inserted entry's ID), so upsert() returned the wrong ID for existing entries. It now returns the entry's ID.
  • Search treated % and _ as wildcards. Search terms are now escaped with $wpdb->esc_like().
  • Invalid orderby caused a database error. search() now only orders by a known column, falling back to created_at.
  • delete_by_ids() with no IDs ran an invalid IN () query. It now returns early.
  • Bulk actions check current_user_can( 'manage_options' ), and the export is sent as text/csv; charset=utf-8 instead of application/x-msdownload.

Testing

New Integration tests in FormEntriesTest, which fail on main and pass with this PR:

  • testUpdateEntryReturnsEntryID
  • testUpsertExistingEntryReturnsEntryID
  • testDeleteEntriesWithNoIDs
  • testSearchWithWildcardCharacters
  • testSearchWithInvalidOrderBy
  • testGetCSVStringEscapesDoubleQuotes
  • testGetCSVStringEscapesFormulas

Existing FormEntriesTest and PluginSettingsFormEntriesCest tests pass unchanged.

For the %i change, FormEntriesTest was also run against WordPress 6.1.7. It fails on main (the table isn't created) and passes with this PR. A one-off check confirmed the 3.0.4 upgrade routine now adds the form_id column on 6.1.7. CI only tests the latest WordPress version, so neither check is included as an automated test.

Checklist

@n7studios n7studios added this to the 3.4.6 milestone Oct 1, 2026
@n7studios n7studios self-assigned this Oct 1, 2026
@n7studios n7studios added the bug label Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

WordPress Playground

🚀 Your PR has been built and is ready for testing in WordPress Playground!

Click here to test your changes in WordPress Playground

@n7studios
n7studios marked this pull request as ready for review October 1, 2026 10:41
@n7studios
n7studios requested review from a team, ciccio-kit and noelherrick and removed request for a team October 1, 2026 10:41
@n7studios
n7studios marked this pull request as draft October 2, 2026 02:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

1 participant