From 3c66bd6cb644ea97d482707290d6683eb07c1eac Mon Sep 17 00:00:00 2001 From: Scott Taylor Date: Tue, 22 Sep 2015 04:31:25 +0000 Subject: [PATCH] Sanitization: when falling back to (wait for it...) `$fallback` in `sanitize_html_class()`, sanitize it as well. Props MikeHansenMe, wonderboymusic. Fixes #30967. Built from https://develop.svn.wordpress.org/trunk@34377 git-svn-id: http://core.svn.wordpress.org/trunk@34341 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-includes/formatting.php | 6 +++--- wp-includes/version.php | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/wp-includes/formatting.php b/wp-includes/formatting.php index 9902cf95c1..e2d8c95552 100644 --- a/wp-includes/formatting.php +++ b/wp-includes/formatting.php @@ -1600,9 +1600,9 @@ function sanitize_html_class( $class, $fallback = '' ) { //Limit to A-Z,a-z,0-9,_,- $sanitized = preg_replace( '/[^A-Za-z0-9_-]/', '', $sanitized ); - if ( '' == $sanitized ) - $sanitized = $fallback; - + if ( '' == $sanitized && $fallback ) { + return sanitize_html_class( $fallback ); + } /** * Filter a sanitized HTML class string. * diff --git a/wp-includes/version.php b/wp-includes/version.php index de1d7423f3..aaac9ee0fe 100644 --- a/wp-includes/version.php +++ b/wp-includes/version.php @@ -4,7 +4,7 @@ * * @global string $wp_version */ -$wp_version = '4.4-alpha-34376'; +$wp_version = '4.4-alpha-34377'; /** * Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.