Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-36895: WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto

Unauthenticated Cross-Site Scripting (XSS) vulnerability in Tripetto’s Tripetto plugin <= 5.1.4 on WordPress via SVG image upload.

CVE
#sql#xss#vulnerability#web#ios#android#mac#windows#google#git#wordpress#php#rce#perl#auth

Tired of boring and ugly forms in your WordPress site? 😴
Use the Tripetto form builder to make your forms conversational! 🚀
Your visitors will love filling out Tripetto forms! 😍

⚡ Tripetto form builder plugin in a nutshell

  • Build any form you need in our unique form builder: contact form, registration form, customer satisfaction form, reservation form, quiz form, order form, exam form, quote calculation form;
  • Full featured form builder plugin that helps you to create conversational forms;
  • Build your form from scratch, or use one of our form templates to build your form even faster;
  • Everything you need, including all collected form data, stored in the Tripetto form builder plugin, right inside of your own WP Admin;
  • Advanced form calculator block included to create quiz forms, order forms, exam forms and more (learn more);
  • Built-in SPAM-protection without the need for using CAPTCHAs in your forms (learn more);
  • Automate form data workflows with notifications (email/Slack), webhook connections to 1.000+ services and form activity tracking;
  • All in a no-code form builder plugin that’s right inside of your own WP Admin;
  • Integrated with WordPress’ most popular content editors and page builders. Easily embed your forms with the shortcode, Gutenberg block or Elementor widget.
  • No third-party account needed, not even a Tripetto account;
  • GDPR proof.

See our full form builder features here.

🧐 What makes Tripetto a better form builder plugin?

💡 With the Tripetto form builder plugin you create stunning custom form experiences instead of boring forms. You can use all your forms in three form faces:

  • Autoscroll form face: the autoscroll form face presents one question at a time and is akin to Typeform’s conversational forms;
  • Chat form face: the chat form face presents all questions and answers as speech bubbles and is partly inspired by Landbot;
  • Classic form face: the classic form face presents question fields in a traditional form as often seen in SurveyMonkey and the likes.

Just use the form face that suits your form and purpose best. Learn more about form faces.

💡 With the Tripetto form builder plugin you create smart forms that react to the given answers of your respondents. That’s why we call them conversational forms. To help you with this, our unique visual form builder easily lets you create the right logic, like branch logic, jump logic and pipe logic. Learn more about form logic.

💡 With the Tripetto form builder plugin you create interactive quizzes, order forms, exams and more with the calculator block. Use given answers of your respondents to perform any calculation you need in your form. The calculator block can add, subtract, multiply and divide, but also supports formulas and advanced mathematical functions. The result: fully no-code calculator forms! Learn more about calculations.

💡 With the Tripetto form builder plugin you create beautiful responsive forms that match your website perfectly, with custom welcome and end screens, advanced styling options and full translations. Your forms are totally responsive for mobile, tablet, laptop and desktop usage. Learn more about customizations.

💡 With the Tripetto form builder plugin you easily automate your form data workflows. Receive notifications, connect to 1.000+ services and track form activity. Learn more about automations.

👷 Give shape – Easily build your forms

  • Start a new form from scratch, or kickstart your form building with one of the form templates that are included in the form builder plugin;
  • Build forms visually on the assistive storyboard, unlike any other form builder;
  • Real-time preview while building your form in the form builder;
  • All question types you need are included in the form builder. See FAQ section below for the full list;
  • Add a custom welcome message before the form starts;
  • Add a custom closing message at the end of the form, or redirect to another page when the form is completed.

Learn more about building your forms.

🤯 Add brains – Make your forms smart

  • Our form builder includes advanced logic features to make your form feel like a conversation;
  • Easy to use but very powerful thanks to Tripetto’s visual form builder;
  • Various types of advanced form logic making it a conversational form;
  • Branch logic, to only ask the right follow-up questions;
  • Skip logic, to jump over unnessecary questions;
  • Pipe logic, to show given answers inside your form;
  • Add flexible closing messages and redirects, based on your logic;
  • Perform real-time calculations inside your forms with the calculator block in the form builder (Pro);
  • Use no-code action blocks in the form builder to work with variables, values and hidden fields (Pro);
  • Send emails to yourself and/or respondents with the send email block in the form builder (Pro).

Learn more about using logic in your forms.

🎨 Dress up – Customize your forms to your needs

  • Choose between three form experiences in the form builder: autoscroll, chat, or classic;
  • Choose autoscroll for a conversational form, for example a quiz form, feedback form, screening form or large survey;
  • Choose chat for a chat form that feels like a chatbot, for example a support form, evaluation form (incl. Net Promoter Score/NPS) or RSVP form;
  • Choose classic for a traditional looking but smart form, for example a contact form, reservation form or registration form;
  • Style your forms in the form builder (fonts, colors, backgrounds, buttons, inputs);
  • All forms are fully optimized for perfect responsiveness on mobile, tablet, laptop and desktop;
  • Translate/edit all labels inside your forms in the form builder;
  • Remove Tripetto branding (Pro).

Learn more about styling and customizing your forms.

⚡ Hook up – Automate things

  • Receive email and Slack notifications upon form completion (Pro);
  • Connect your responses to 1.000+ services via Make, Zapier, Pabbly and custom webhooks (Pro);
  • Track how your respondents use your forms with form activity tracking via Google Analytics, Google Tag Manager, Facebook Pixel and custom tracking codes (Pro).

Learn more about automating your form data.

📣 Send out – Share forms how you wish

  • Immediately share your form with the shareable link in your WP site, making your WP site a complete form tool/survey tool instantly;
  • Or embed the form wherever you want with the WP shortcode. Compose your shortcode exactly like you want to embed your form with the shortcode editor in the form builder (no-code);
  • Or embed Tripetto forms right inside WordPress’ Gutenberg editor. Easily build, customize and automate your forms without leaving the Gutenberg editor;
  • Or embed Tripetto forms into your Elementor pages and popups with our Elementor widget.

Learn more about sharing your forms.

🛡️ Take stock – Handle form responses safely

  • Form responses are stored in your own WordPress install/database only (no third-party storage);
  • SPAM protection is built right into your forms, so no need for CAPTCHAs etc.;
  • View and manage form results inside your WP Admin;
  • Export form results to CSV.

Learn more about data management of your forms.

🥇 Pro features

Upgrade the Tripetto WordPress form builder plugin to push your forms to the next level and greatly enhance all your forms and surveys. Pro features are:

Unlimited form building – No limits in our form builder:

  • Unlimited forms
  • Unlimited logic per form
  • Unlimited questions per form
  • Unlimited responses per form
  • Unlimited usage of Pro form templates

All action blocks – Perform advanced actions in your form:

  • Calculator
  • Custom variable
  • Force stop
  • Hidden field
  • Raise error
  • Send email
  • Set value

Tripetto unbranding – Remove Tripetto branding:

  • Remove Tripetto branding in forms
  • Remove Tripetto branding in emails

Notifications – Receive instant notifications for new form responses:

  • Email notifications, including all form data
  • Slack notifications, including all form data

Connections – Connect your form responses to 1.000+ services using webhooks:

  • Connect form data with Make (formerly Integromat)
  • Connect form data with Zapier
  • Connect form data with Pabbly Connect
  • Connect form data with custom webhooks

Activity tracking – Track form activity of your respondents:

  • Track form activity with Google Analytics
  • Track form activity with Google Tag Manager
  • Track form activity with Facebook Pixel
  • Track form activity with custom tracking codes

WordPress roles management – Configure plugin access and capabilities:

  • User role access settings
  • User role capabilities settings

Priority support + updates – Be assured of priority support and all plugin updates:

  • Access to help center [24/7]
  • Prio support [Mon-Fri, 9-17 CET]
  • All updates and upgrades

👉 Get your Pro license today!
Available as single-site, 5-sites and unlimited sites.

🧰 Available as Gutenberg block

Tripetto’s fullblown form builder is also available right inside the WordPress Gutenberg editor. The Tripetto Gutenberg block makes it easy to build, customize and automate your forms without leaving the Gutenberg editor.

  • Add existing forms or build a new form right inside WordPress’ Gutenberg editor;
  • Build, customize and automate your forms without leaving the Gutenberg editor. All form builder features are available right inside the Gutenberg editor;
  • See a live preview of your form in the Gutenberg editor, so you’ll constantly see and feel how your form will blend with the rest of your content.

Learn more about Tripetto in the Gutenberg editor

🧰 Available as Elementor widget

Tripetto forms are also available in Elementor. The Tripetto Elementor widget lets you easily embed your forms into pages and popups that you create with Elementor.

Learn more about Tripetto in the Elementor builder

🕵️‍♂️ Compare Tripetto with others

We are the new kid on the block in the form builder world, so we understand that a comparison will help you decide if Tripetto is the right form builder for you.

  • Compare Tripetto with WPForms
  • Compare Tripetto with Contact Form 7
  • Compare Tripetto with Ninja Forms
  • Compare Tripetto with Gravity Forms
  • Compare Tripetto with Typeform

Compare Tripetto with other form builders.

🔔 Stay up-to-date

Any questions about our form builder or your forms? We’re happy to help!

  • Help Center
  • Contact us
  • Subscribe to our newsletter
  • Follow us on Twitter

Translations

The following translations are included:

  • English (default)
  • Dutch (Nederlands)
  • French (Français)
  • Indonesian (Indonesia)
  • Polish (Polski)

Note: This plugin is designed to be fully localized and translatable, but we need help to translate it to other languages. Take a look at our translations repository to see what needs to be done and how you can contribute.

✔️ New feature
⚡ Improvement
🐛 Bugfix
❌ Deprecated or removed feature

VERSION 5.3.2 (28-02-2022)
🐛 Fixed a bug where assets for the Gutenberg block were loaded when not needed

VERSION 5.3.1 (25-02-2022)
⚡ Migrate Integromat to Make
⚡ Tested compatibility with WordPress 5.9.1
🐛 Fixed a bug in the attachment download service

VERSION 5.3.0 (17-02-2022)
✔️ Added a build new form page that includes a gallery of form templates to choose from
✔️ Added an option to store a concatenated text with all the selected options in the dataset (available for the checkboxes, multiple-choice, and picture-choice blocks)
✔️ Added Google Tag Manager support for form tracking
✔️ Added an option to configure trackers to use global tracker codes when embedding forms
✔️ Added the possibility to retrieve a result overview page by result reference (using the reference query string parameter)
✔️ Added a WordPress filter hook tripetto_prefill that allows programmatically prefilling data in forms
⚡ Improved the exportability feature to make it clearer what this feature does
⚡ Tested compatibility with WordPress 5.9
🐛 Fixed submission issues when using Safari with response data that contains combining diacritical marks
🐛 Fixed a bug where icons in buttons would turn the wrong color when hovering over the button
🐛 Fixed a bug in the required feature of the matrix block

VERSION 5.2.0 (22-11-2021)
✔️ Added limits feature (minimum/maximum text length) to multi-line text
🐛 Fixed an XSS vulnerability when uploading malicious SVG files (thanks to thiennv/Patchstack for reporting this issue)

VERSION 5.1.5 (03-11-2021)
⚡ Update dashboard

VERSION 5.1.4 (21-10-2021)
⚡ Improved retry mechanism and error handling when saving forms (reduces issues with unstable hosts)
⚡ Improved chat button visibility for small devices

VERSION 5.1.3 (18-10-2021)
🐛 Fixed a bug in the conflict detection component

VERSION 5.1.2 (14-10-2021)
🐛 Fixed a bug where the builder stopped working when an evaluate block was added after a cluster without any nodes

VERSION 5.1.1 (23-09-2021)
⚡ Improved the onboarding tutorial with instruction videos about using the Gutenberg block and the Elementor widget

VERSION 5.1.0 (23-09-2021)
✔️ Added a widget for Elementor (see https://tripetto.com/blog/another-update-tripetto-as-elementor-widget/)
🐛 Fixed a bug where the builder could not load on hosts where mbstring support for PHP was not enabled

VERSION 5.0.1 (16-09-2021)
✔️ Added a full-featured Gutenberg block for Tripetto (see https://tripetto.com/blog/major-update-tripetto-as-gutenberg-block/)
✔️ Added the possibility to customize the columns of the result list
⚡ Added protection to detect conflicts when working with multiple users (or browser tabs/windows) on the same form
⚡ Improved the header bar of the list views
⚡ Added a style setting to the runners to customize the font size for small screens (mobile devices)
⚡ Made the tripetto_create_forms capability dependent on the tripetto_edit_forms capability (so a user needs both capabilities to be able to create new forms)
🐛 Fixed a bug where pausing the form with an invalid email address would freeze the form
🐛 Fixed a bug where the builder could not load when a malformed custom tracking code was supplied

VERSION 4.2.4 (07-09-2021)
🐛 Fixed a bug in the address validation of the email block
🐛 Fixed a bug in the calculator where an outcome was not always available immediately
🐛 Fixed a bug where duplicate fields were shown in the classic runner
🐛 Fixed a bug in the download handler of uploaded files
🐛 Fixed a bug where the headers of CSV files were missing when using PHP <= 5.6
🐛 Fixed a bug in the custom WordPress hook (tripetto_submit)

VERSION 4.2.3 (04-08-2021)
🐛 Fixed missing information in the dashboard

VERSION 4.2.2 (03-08-2021)
🐛 Fixed a bug in the email notification service (messages were not sent in some cases)

VERSION 4.2.1 (29-07-2021)
✔️ Added a WordPress filter hook tripetto_webhook that allows altering data that is sent to the custom webhook
🐛 Fixed a bug in the WordPress action hook implementation where the wrong data was supplied to the hook

VERSION 4.2.0 (29-07-2021)
✔️ Added tracking support for Google Analytics, Facebook Pixel or a custom tracker code (see https://tripetto.com/blog/new-feature-form-activity-tracking-with-google-analytics-and-facebook-pixel/)
✔️ Added Zapier feature to the connections panel
✔️ Added Integromat feature to the connections panel
✔️ Added Pably Connect feature to the connections panel
✔️ Added a WordPress filter hook tripetto_styles that allows altering style settings of forms
✔️ Added French translation (🙏 Benjamin COUEDEL)
⚡ Improved the automate menu (there are now separate panels for managing notifications, connections and tracking)
⚡ Improved trackpad support for the form builder (now supports panning in all directions)
⚡ Improved test function for Slack notifications and webhooks (fields of the form are now submitted as test data)
🐛 Fixed an issue where settings in the automate panels would not be saved

VERSION 4.1.1 (23-07-2021)
✔️ Added limiting feature to limit the number of selected options/answers (available for the checkboxes, multiple choice, and picture choice blocks)
✔️ Added randomization feature (available for the dropdown, checkboxes, multiple choice, picture choice, and radio buttons blocks)
✔️ Added counter slot that counts the number of selected options/answers (available for the checkboxes, multiple choice, and picture choice blocks)
🐛 Fixed a compatibility issue with Happy Addons for Elementor (see https://wordpress.org/support/topic/add_menu_page-breaking-other-plugins/)
🐛 Fixed a bug where recalling values of other blocks did not work properly for specific cases
🐛 Fixed a bug where administrators in multisite installations could not access Tripetto
🐛 Fixed a bug where style changes in the chat form were not applied to the live preview panel

VERSION 4.1.0 (15-07-2021)
✔️ Added WordPress variables to the hidden field block (see https://tripetto.com/blog/new-feature-instantly-use-wordpress-variables-in-your-forms/)
🐛 Fixed a bug where the builder screen was shown behind the WordPress menu
🐛 Fixed a bug where branch iterations would sometimes not display correctly
🐛 Fixed a bug where conflicts occurred when the same form was used multiple times on the same page
🐛 Fixed a bug where activation of both the free and pro version of the plugin could result in a plugin activation error

VERSION 4.0.4 (08-07-2021)
🐛 Fixed a bug where some users could not activate the plugin properly

VERSION 4.0.3 (06-07-2021)
🐛 Fixed a compatibility issue with WordPress 5.0 or lower
🐛 Fixed a bug in the pause and resume function

VERSION 4.0.1 (01-07-2021)
✔️ Implemented roles and capabilities support
✔️ Added a settings page to manage global settings for Tripetto
✔️ Added a setting to disable the SPAM-protection system
✔️ Added an IP address allowlist for the SPAM-protection system
✔️ Added a setting to set the sender address for emails sent by Tripetto
✔️ Added an onboarding wizard to help configuring and using the plugin
✔️ Added new branch mode for checking if none of the conditions match (logical NOT)
✔️ Added automatic video playback and pausing
✔️ Added a new constant to the calculator to find the current branch index number
⚡ Improved the webhook (it now allows URLs with a username and password in it)
⚡ Renamed the premium plan to pro
⚡ Improved block type selection when adding a new block
⚡ Added a style setting to remove the asterisk for required blocks (only applies to the autoscroll and classic runner)
⚡ Improved variables support in URLs so you can use a variable to specify the protocol and domain part of an URL
⚡ Improved the multiple choice and picture choice blocks so you can select a hyperlink target for URL choices
⚡ Improved dashboard with help articles and video tutorials
🐛 Fixed a typo in the mailer block

VERSION 3.5.1 (31-05-2021)
⚡ Improved the URL block
🐛 Fixed a data regression bug causing some forms to not work properly

VERSION 3.5.0 (27-05-2021)
✔️ Added settings to the automate panel to make uploaded files in forms directly accessible for webhooks and Slack/email recipients
🐛 Fixed a bug in the closing message of the classic runner
🐛 Fixed a bug in the capitalize function (see https://gitlab.com/tripetto/studio/-/issues/40)

VERSION 3.4.3 (20-05-2021)
✔️ Added count occurrences function to the calculator block
✔️ Added concatenate option to the set value block
✔️ Added an option to disable scrolling in the autoscroll runner
✔️ Implemented Trusted Types support (see https://web.dev/trusted-types/)
✔️ Added German translation for the runners (form faces)
✔️ Added French translation for the runners (form faces)
✔️ Added Spanish translation for the runners (form faces)
✔️ Added Portuguese translation for the runners (form faces)
✔️ Added Indonesian translation (🙏 https://gitlab.com/hisamafahri)
✔️ Added additional alias options to the yes/no block
⚡ Improved performance for very large forms
⚡ Improved the live preview of the classic runner
⚡ Improved usability of the set value block
⚡ Improved the icons on the dashboard page
⚡ Improved the size of the plugin (reduced the plugin ZIP file by 1.38Mb)
🐛 Fixed a bug in the number field where the formatting was not applied
🐛 Fixed a bug in the calculator feature of the number block
🐛 Fixed a bug in the classic runner where sections with no blocks (or only invisible blocks) caused paginated forms to stop working
🐛 Fixed a bug with the submit button in the multiple choice and picture choice block
🐛 Fixed a bug in the translation system where the wrong translation was used
🐛 Fixed the date/time in the list of forms and results
🐛 Fixed an accessibility issue with the dropdown lists in the runners (form faces)

VERSION 3.3.1 (17-02-2021)
✔️ Added an import/export function to allow easy adding of multiple items at once (for example, dropdown options, multiple choice buttons, text suggestions, etc.)
✔️ Added a custom variable block that allows the use of custom variables
✔️ Added a set value block that allows to set field values or other variables
✔️ Added suggestions support in the single line text block so you can specify a list of pre-defined options for the text input
✔️ Added a score feature to blocks so you can calculate scores directly without the need of a separate calculator block (this works for the blocks checkbox, checkboxes, dropdown, matrix, multiple choice, picture choice, radiobuttons, scale, single line text and yes/no)
✔️ Added a calculator option to the number block, so you can make successive calculations directly without the need of a separate calculator block
✔️ Added a prefill setting to the number, single line text and multiple lines text blocks so you can set an initial value for those fields (if you want to set an initial value for other blocks, use the new set value block)
✔️ Added a minimum required text length option to the single line text block
⚡ Enabled a scrollbar for menus with lots of options (you can grab the scrollbar to quickly scroll through all items in the menu)
⚡ Changed the initial behavior of a subcalculation within a calculator block: The initial value is now set to the last answer (ANS) of the parent calculation instead of an empty value (please check your form if you are using subcalculations as this change might break things for you)
⚡ Improved the calculator behavior when using variables that have no value yet as input (this will only lead to an invalid calculation when that variable is used as initial input, for multiplication, or for division, otherwise the variable input will be considered 0)
🐛 Fixed a keyboard bug in MacOS Safari where the text cursor sometimes jumped to end of a line (https://gitlab.com/tripetto/studio/-/issues/28)
🐛 Fixed the mobile keyboard for numeric fields with decimal precision
🐛 Fixed a bug where the label of a node was not displayed properly (https://gitlab.com/tripetto/studio/-/issues/31)
🐛 Fixed a bug in the allowed file types setting of the file upload block
🐛 Fixed a bug in the closing message where sometimes the wrong message was shown
🐛 Fixed a bug in the radio button block in the chat runner
🐛 Fixed a query string bug in Internet Explorer
🐛 Fixed a bug where downloads would not work when wp-admin lives in a sub folder
🐛 Fixed a bug where in some specific cases a form could not be submitted
🐛 Fixed a compatibility bug with PHP <= 5.6

VERSION 3.2.0 (12-01-2021)
✔️ Added a calculator block that allows (advanced) calculations inside forms (see https://tripetto.com/no-code-calculations-with-the-calculator-block/)
✔️ Added a stop block that can be used to prevent completion of a form
⚡ Improved condition logic (you can now use values of other blocks)
⚡ Improved switching between block types (more block settings are now retained)
⚡ Improved markdown support for checkboxes and radio buttons
⚡ Implemented variables support in dropdown options, multiple choice items and picture choice items
⚡ Implemented an option to set readable labels for boolean (true/false) values
🐛 Fixed an alignment bug in the mobile view of the Autoscroll runner
🐛 Fixed the usage of variables inside image/video URLs
🐛 Fixed a bug where the identifier of a form response was not available in the closing message of nested branches
🐛 Fixed a bug where an illegal custom font name would lead to a runner fault
🐛 Fixed a bug in the file upload condition block

VERSION 3.1.13 (15-12-2020)
⚡ Tested compatibility with WordPress 5.6 and PHP 8
🐛 Fixed an issue with headers already sent

VERSION 3.1.12 (09-12-2020)
🐛 Fixed a bug in the mail notification service

VERSION 3.1.11 (07-12-2020)
🐛 Fixed a bug in the result viewer

VERSION 3.1.10 (03-12-2020)
🐛 Fixed a bug in duplicate form function
🐛 Fixed a bug in redirect to another URL after form completion

VERSION 3.1.8 (23-11-2020)
🐛 Fixed a problem with (Cloudflare) caching (added a Cache-Control header)

VERSION 3.1.7 (18-11-2020)
✔️ Added shortcode attribute placeholder to define a loader message (this message is shown while the form is loading)
⚡ Improved the shortcode editor so the loader message can be managed
🐛 Fixed a bug where a form could not load due to insufficient permissions of the plugin’s own AJAX handler

VERSION 3.1.6 (17-11-2020)
⚡ Improved form loading performance (especially on slow-hosted websites)

VERSION 3.1.5 (13-11-2020)
✔️ Added shortcode attribute async to control the loading method of forms inside pages
🐛 Fixed a bug in branch iteration logic
🐛 Fixed a bug in scale block

VERSION 3.1.4 (04-11-2020)
🐛 Fixed a bug in the translation editor
🐛 Fixed a bug in the SPAM-protection system on 32-bit legacy systems

VERSION 3.1.3 (21-10-2020)
⚡ Improved compatibility with cache plugins
⚡ Improved error messages
🐛 Fixed a bug where the Tripetto branding was still visible in the email messages sent by the plugin
🐛 Fixed a bug where database migrations (from old plugin version a newer one) sometimes resulted in an error
🐛 Fixed a bug related to font ligatures

VERSION 3.1.2 (14-10-2020)
🐛 Fixed a bug where the Hindi keyboard on iOS could not be used properly

VERSION 3.1.1 (13-10-2020)
🐛 Fixed compatibility with 32-bit legacy systems (fixes a problem with the SPAM-protection system not working correctly on PHP without 64-bit support)

VERSION 3.1.0 (10-10-2020)
✔️ Added picture choice block
✔️ Added scale block
⚡ Added more shapes to the rating block
⚡ Improved rating block conditions
⚡ Improved URL block (if the protocol prefix is missing, it is added automatically on blur)
⚡ Allow relative URLs for images and fonts
⚡ Switched to RFC5322 for email validation (which is more strict)
⚡ Auto-focus is now set to the selected button/option whenever possible
🐛 Fixed a bug in the web font loader

VERSION 3.0.7 (06-10-2020)
🐛 Fixed bug in chat window positioning
🐛 Fixed compatibility with MySQL versions lower than 5.6.5

VERSION 3.0.6 (05-10-2020)
🐛 Fixed bug in mobile responsiveness (see https://gitlab.com/tripetto/wordpress/-/issues/88)
🐛 Fixed compatibility with PHP 5.6

VERSION 3.0.5 (02-10-2020)
🐛 Improved compatibility with W3 Total Cache
🐛 Improved compatibility with Autoptimize
🐛 Fixed a bug where the font Fira Sans could not be used in Firefox
🐛 Added missing label in translation settings for the autoscroll runner

VERSION 3.0.4 (30-09-2020)
✔️ Added a style option to set the opacity of the background image in the runners
⚡ Improved the multiple choice buttons (they now wrap to the next line when necessary)
⚡ Automatically remove empty checkboxes, multiple choice buttons and radio buttons when in live or test mode (preview mode still shows placeholders for empty options)
🐛 Fixed a bug in the SPAM-protection system (this solves submission errors as reported by some of our users)
🐛 Fixed the z-index of the chat runner in inline mode
🐛 Fixed a compatibility issue with the WP AMP plugin
🐛 Fixed a bug where the Tripetto branding was not removed for free premium forms

VERSION 3.0.3 (18-09-2020)
🐛 Fixed bug in migration component

VERSION 3.0.2 (18-09-2020)
✔️ Added autoscroll runner
✔️ Added chat runner
✔️ Added classic runner
✔️ Added custom welcome message support
✔️ Added custom closing message support (supports alternative closing messages per branch)
✔️ Added URL redirect support
✔️ Added pause and resume support
✔️ Added standalone mode (allows forms to run standalone without the need of using a shortcode on a page; your WordPress instance is now a full-blown survey tool!)
✔️ Added date/time block
✔️ Added telephone block
✔️ Added error action block
✔️ Added evaluate condition block
✔️ Added regex condition block
✔️ Added translation support for static labels/texts in forms
✔️ Added identification number of each result to the results list
✔️ Added shortcode editor for easy configuration of shortcodes
✔️ Added persistent mode (this allows forms to maintain their state/session between page navigation)
✔️ Added dutch plugin translation
✔️ Added links to help articles
✔️ Added custom hooks to catch form submissions (tripetto_submit) and pause requests (tripetto_pause)
⚡ Upgraded builder to latest and greatest version (lots of improvements under the hood there; too much to list here)
⚡ Migrated rolling collector to autoscroll runner
⚡ Migrated classic bootstrap collector to classic runner
⚡ Improved mailer block (add reply-to header support and option to include all data)
⚡ Improved styling options to allow way more customizations
⚡ Improved SPAM-protection (no need for CAPTCHAs in Tripetto, we have a different mechanism to fight form spamming)
⚡ Improved automation tests
⚡ Improved shortcodes for better support of multiple forms on a single page
⚡ Improved inline behavior of forms (no more style conflicts)
⚡ You can now customize the styles of all your forms (in previous versions only premium forms could be customized)
⚡ Changed the CSV delimiter to semicolon instead of comma (better for Excel and the behavior now aligns with the Tripetto Studio)
⚡ Changed the CSV sorting to descending (the behavior now aligns with the Tripetto Studio)
⚡ Renamed entries to results (to align the terms used with Tripetto Studio)
🐛 Fixed a bug in the validation of empty number fields
🐛 Fixed a bug while filling out number fields in Firefox browser
🐛 Fixed the unwanted behavior of the first radio button getting selected for required radio button questions
🐛 Fixed a bug on Android devices having difficulty with showing the soft-keyboard while filling out the form
🐛 Fixed the unwanted ability to create ‘infinite loops’ inside your form, resulting in a freezing form
🐛 Fixed a bug where partial or broken definitions could be saved to the database
❌ Removed the single free premium form (you now always need a paid license to use premium features)
❌ Removed the feedback-for-a-premium-license form (thanks to everyone who filled it in; you made Tripetto better!)

VERSION 2.2.5 (30-04-2020)
🐛 Fixed a bug where large data sets could not be saved to the database

VERSION 2.2.3 (08-10-2019)
🐛 Fixed a bug in the hidden field block

VERSION 2.2.1 (10-09-2019)
🐛 Fixed a bug in the markdown parser
🐛 Fixed a bug where the collector sometimes didn’t load on certain pages
🐛 Fixed a bug where Wordfence mistakenly thought a script was malicious

VERSION 2.1.3 (04-09-2019)
🐛 Fixed a bug where the plugin would not work with MySQL version 5.5 (or older)

VERSION 2.1.2 (28-08-2019)
🐛 Fixed a bug where the wrong plugin directory was used

VERSION 2.0.4 (27-08-2019)
⚡ Removed jQuery dependency

VERSION 2.0.3 (21-08-2019)
🐛 Fixed issue #77 (https://gitlab.com/tripetto/wordpress/issues/77)
🐛 Fixed a bug in the file upload handling

VERSION 2.0.1 (09-08-2019)
✔️ Added a brand new collector with a standard UI based on Bootstrap (for those who want to create a more traditional form)
✔️ Added a toggle to the header bar in the edit screen to switch between the Rolling UI or the new Standard UI
✔️ Added a toggle to the header bar in the edit screen to switch between edit mode and test mode (in edit mode all blocks are displayed in the preview pane, test mode runs the form with all logic enabled so you can test it)
✔️ Added edit buttons in the preview pane to quickly open the properties of a block
✔️ Automatically scroll blocks into view when they are edited
⚡ Improved the header bar in the editor screen to incorporate all the new options (moved the device toggle buttons to a separate dropdown)
⚡ Improved the shortcode so it is not necessary anymore to specify a height for the form (you still can specify a fixed height if you want)
⚡ Installed the latest and greatest version of the Rolling UI collector
🐛 Fixed a bug that caused problems when 2 or more forms were placed on the same page

VERSION 1.4.2 (31-07-2019)
🐛 Fixed a bug with the sender’s name in email notifications (#76)

VERSION 1.4.0 (25-07-2019)
✔️ Added an option to generate random values with the hidden field block
✔️ Added the option to align the first block of the collector at the top instead of the center of the screen
⚡ Moved some collector options (navigation bar, enumerators, etc.) to the styles section of the settings panel
⚡ Upgraded to a new version of the rolling collector with improved performance and also some bug fixes

VERSION 1.3.0 (17-07-2019)
✔️ Added hidden field block (this allows the use of hidden fields in forms and also logic based on the value of those hidden fields)

VERSION 1.2.1 (16-07-2019)
✔️ Added the option to include the form data in confirmation mails
✔️ Added the “Send an email”-block to send emails from within forms
🐛 Fixed bug in the editor position when WP menu is collapsed
🐛 Fixed a bug in keyboard navigation in the collector
🐛 Fixed a bug where focus sometimes was set on the wrong field in the settings panel of the editor

VERSION 1.1.11 (10-07-2019)
✔️ Added multiple checkboxes block
✔️ Added radiobuttons block
✔️ Added the possibility to hide the title of a block
🐛 Fixed problem with the style of the checkbox block
⚡ Renamed Next button to Ok button

VERSION 1.1.8 (09-07-2019)
✔️ Added single checkbox block
✔️ Added ability to change the labels of the Next and Complete buttons in the form style panel
✔️ Added uninstall script to remove the data tables when the plugin is deleted
🐛 Automatically make blocks required when the required feature is enabled (this saves an additional click by the user)
🐛 Fixed a bug in the positioning of the empty message of the collector

VERSION 1.1.5 (02-07-2019)
✔️ Confirmation dialogs when a form or entry is about to be deleted
🐛 Fixed a bug in the Zapier-integration
⚡ Unlocked all premium functionality for one form without the need of having a paid license

VERSION 1.0.0 (14-06-2019)
👶 A new plugin is born, Tripetto is now in the WordPress Plugin Directory!

Related news

CVE-2022-27888: security-bulletins/PLTRSEC-2022-01.md at main · palantir/security-bulletins

Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This issue was fixed in Fixed in 2.249.1.

CVE-2022-27854: Psychological tests & quizzes

Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19 on WordPress possible for users with contributor or higher role via &wpt_test_page_submit_button_caption parameter.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907