WordPress自定义插件:数据库插入实现及表单路径问题求助
Hey there! Let's fix your form submission issue and get that database insertion working smoothly in your custom WordPress plugin. I'll walk you through the right steps, since your path problem and missing WordPress environment setup are likely the main culprits.
1. Fix the Form Action Path
First, your initial mistake was using plugin_dir_path() — that returns a server-side file system path (like /home/your-site/wp-content/plugins/your-plugin/), which browsers can't interpret as a web address. You need a web-accessible URL instead, so use plugin_dir_url() instead. Also, always sanitize URLs with esc_url() for security.
Here's the corrected form code if you still want to use your standalone page_options.php file:
<form method="post" action="<?php echo esc_url( plugin_dir_url( __FILE__ ) . 'page_options.php' ); ?>"> <!-- Your input fields go here --> <input type="submit" name="send" value="Submit"> </form>
But wait — using a standalone file isn't the most WordPress-friendly approach. It requires manually loading the WordPress environment, which can lead to security gaps. Let's use WordPress's built-in admin_post action instead, which is the standard way to handle form submissions in plugins.
2. Use WordPress's admin_post Hook (Recommended)
This method avoids needing a separate file and leverages WordPress's security and environment setup. Here's how to implement it:
Step 1: Register the Submission Handler in Your Main Plugin File
Add this code to your plugin's main PHP file to handle form submissions:
// Register handlers for logged-in and non-logged-in users (remove the nopriv line if you only want logged-in access) add_action( 'admin_post_save_my_custom_data', 'handle_my_plugin_form_submission' ); add_action( 'admin_post_nopriv_save_my_custom_data', 'handle_my_plugin_form_submission' ); function handle_my_plugin_form_submission() { // Check user permissions (adjust the capability based on your plugin's needs) if ( ! current_user_can( 'manage_options' ) ) { wp_die( 'You don’t have permission to do that.' ); } // Verify nonce to prevent CSRF attacks (critical for security!) check_admin_referer( 'my_plugin_form_nonce', 'form_nonce' ); // Sanitize form inputs to prevent SQL injection and XSS $your_field = sanitize_text_field( $_POST['your_field_name'] ); $another_field = sanitize_email( $_POST['another_field'] ); // Use appropriate sanitization for each field // Insert data into your custom table using WordPress's $wpdb class global $wpdb; $custom_table = $wpdb->prefix . 'your_table_name'; // Always use the WP prefix to avoid conflicts $insert_result = $wpdb->insert( $custom_table, array( 'column_one' => $your_field, 'column_two' => $another_field ), array( '%s', // Data type for column_one (string) '%s' // Data type for column_two (adjust to %d for integer, %f for float, etc.) ) ); // Handle success or failure if ( $insert_result ) { // Redirect back to your plugin page with a success message wp_redirect( admin_url( 'admin.php?page=your_plugin_menu_slug&status=success' ) ); exit; } else { wp_die( 'Oops, something went wrong: ' . $wpdb->last_error ); } }
Step 2: Update Your Form to Use the admin_post Endpoint
Modify your form to submit to WordPress's built-in handler, and add a nonce for security:
<form method="post" action="<?php echo esc_url( admin_url( 'admin-post.php' ) ); ?>"> <?php wp_nonce_field( 'my_plugin_form_nonce', 'form_nonce' ); ?> <input type="hidden" name="action" value="save_my_custom_data"> <!-- Matches the action in our hook --> <!-- Your input fields --> <input type="text" name="your_field_name" placeholder="Enter some text"> <input type="email" name="another_field" placeholder="Enter your email"> <input type="submit" name="send" value="Submit"> </form>
Key Notes to Remember
- Security First: Always sanitize user input, use nonces, and check permissions. Never trust raw
$_POSTdata. - WordPress Database Class: Use
$wpdbinstead of writing raw SQL queries — it handles escaping and compatibility across different setups. - Table Prefix: Always prepend
$wpdb->prefixto your custom table name to avoid conflicts with multisite installations or other plugins.
This approach will fix your form submission issue and properly handle database inserts the WordPress way.
内容的提问来源于stack exchange,提问作者Manu

