WordPress插件表单提交报404,无法写入phpMyAdmin求助
Hey there, let's break down your problems step by step—first that frustrating 404 when submitting the form, then all the code issues you mentioned.
The root cause here is that WordPress can't handle direct submissions to your demo.php file. Its rewrite rules and security systems block unregistered PHP file requests in plugin directories. Instead, you need to use WordPress's built-in admin post handling system:
Update your form's action in
classifiedbr.php
Replace your form'sactionattribute with a call to WordPress's admin endpoint, and add a hidden field to identify your submission action:<form method="post" action="<?php echo esc_url(admin_url('admin-post.php')); ?>"> <!-- Add a nonce for security (we'll cover this more later) --> <?php wp_nonce_field('create_custom_user_nonce', 'custom_user_nonce'); ?> <!-- Hidden field to tell WordPress which action to trigger --> <input type="hidden" name="action" value="create_custom_user"> <!-- Your existing form fields (username, email, password, etc.) --> <label for="user_login">Username:</label> <input type="text" name="user_login" id="user_login" required> <!-- ... rest of your form fields ... --> <input type="submit" value="Create User"> </form>Add a handler hook in your plugin's main file
Instead of usingdemo.php, move your submission logic into a function hooked to WordPress's admin post system. Add this to your plugin's main file (or include it fromdemo.phpif you want to keep it separate):// Hook for logged-in admins add_action('admin_post_create_custom_user', 'handle_custom_user_creation'); // If you ever need front-end access, add this too (not needed for admin-only forms) // add_action('admin_post_nopriv_create_custom_user', 'handle_custom_user_creation'); function handle_custom_user_creation() { // We'll add security checks and logic here next // ... // After processing, redirect back to your admin page wp_redirect(esc_url(admin_url('admin.php?page=your_plugin_page_slug'))); exit; }Replace
your_plugin_page_slugwith the actual slug you used when registering your admin page withadd_menu_page()oradd_submenu_page().
Now let's tackle the code problems you mentioned:
1. Replace Deprecated mysql_* Functions
The mysql_* functions are long-deprecated in PHP and WordPress. Use WordPress's built-in $wpdb class instead—it's safer, handles table prefixes automatically, and integrates with WordPress's security:
- Remove all lines like
mysql_connect(),mysql_select_db(), andmysql_query(). - Instead, use
global $wpdbto access the database object.
2. Use WordPress's Built-in User Creation (Instead of Custom SQL)
You don't need to write your own INSERT query—WordPress has wp_create_user() which handles password hashing, duplicate checks, and default user roles automatically:
function handle_custom_user_creation() { // Security first: Check nonce if (!isset($_POST['custom_user_nonce']) || !wp_verify_nonce($_POST['custom_user_nonce'], 'create_custom_user_nonce')) { wp_die('Security check failed. Please go back and try again.'); } // Check user permissions (only admins should create users) if (!current_user_can('manage_options')) { wp_die('You don\'t have permission to create users.'); } // Sanitize all input to prevent XSS and SQL issues $user_login = sanitize_user($_POST['user_login']); $user_email = sanitize_email($_POST['user_email']); $user_pass = $_POST['user_pass']; // Create the user with WordPress's built-in function $user_id = wp_create_user($user_login, $user_pass, $user_email); // Handle errors (like duplicate username/email) if (is_wp_error($user_id)) { // Store error message in session to display on your admin page $_SESSION['user_creation_error'] = $user_id->get_error_message(); } else { $_SESSION['user_creation_success'] = 'User created successfully! User ID: ' . $user_id; } // Redirect back to your admin page wp_redirect(esc_url(admin_url('admin.php?page=your_plugin_page_slug'))); exit; }
3. Fix Variable Overrides & Syntax Errors
- Run your PHP files through a syntax checker (like
php -l your-file.phpin the command line) to catch missing semicolons, mismatched brackets, etc. - Check for duplicate variable names (e.g., if you're reusing
$user_loginin different scopes) that could cause unexpected overrides. - Always sanitize and validate user input (we did this with
sanitize_user()andsanitize_email()above) to avoid messy data breaking your code.
4. Display Success/Error Messages on Your Admin Page
Add this to your classifiedbr.php admin page code to show feedback after submission:
// Check for session messages if (isset($_SESSION['user_creation_success'])) { echo '<div class="notice notice-success is-dismissible"><p>' . esc_html($_SESSION['user_creation_success']) . '</p></div>'; unset($_SESSION['user_creation_success']); } if (isset($_SESSION['user_creation_error'])) { echo '<div class="notice notice-error is-dismissible"><p>' . esc_html($_SESSION['user_creation_error']) . '</p></div>'; unset($_SESSION['user_creation_error']); }
内容的提问来源于stack exchange,提问作者Britchi2

