From 0bbb277ee49c44956996b46be4865247ca0a5bd9 Mon Sep 17 00:00:00 2001 From: Gary Pendergast Date: Wed, 16 Jan 2019 06:05:49 +0000 Subject: [PATCH] Formatting: Add type checking to `_sanitize_text_fields()`. When a non-string value is passed, return an empty string. Props Mte90. Fixes #41450. Built from https://develop.svn.wordpress.org/trunk@44618 git-svn-id: http://core.svn.wordpress.org/trunk@44449 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-includes/formatting.php | 4 ++++ wp-includes/version.php | 2 +- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/wp-includes/formatting.php b/wp-includes/formatting.php index 460a6b8038..e9ab7f37b1 100644 --- a/wp-includes/formatting.php +++ b/wp-includes/formatting.php @@ -5102,6 +5102,10 @@ function sanitize_textarea_field( $str ) { * @return string Sanitized string. */ function _sanitize_text_fields( $str, $keep_newlines = false ) { + if ( ! is_string( $str ) ) { + return ''; + } + $filtered = wp_check_invalid_utf8( $str ); if ( strpos( $filtered, '<' ) !== false ) { diff --git a/wp-includes/version.php b/wp-includes/version.php index 9f22cd2881..5f33d63dc1 100644 --- a/wp-includes/version.php +++ b/wp-includes/version.php @@ -13,7 +13,7 @@ * * @global string $wp_version */ -$wp_version = '5.1-beta1-44617'; +$wp_version = '5.1-beta1-44618'; /** * Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.