mirror of
https://github.com/WordPress/WordPress.git
synced 2024-12-25 02:27:50 +01:00
Use esc_attr() for attributes. Props johnjamesjacoby. fixes #22327
git-svn-id: http://core.svn.wordpress.org/trunk@22373 1a063a9b-81f0-0310-95a4-ce76da25c4cd
This commit is contained in:
parent
e79b028a08
commit
3eabc7db5a
@ -1113,7 +1113,7 @@ function do_settings_fields($page, $section) {
|
|||||||
foreach ( (array) $wp_settings_fields[$page][$section] as $field ) {
|
foreach ( (array) $wp_settings_fields[$page][$section] as $field ) {
|
||||||
echo '<tr valign="top">';
|
echo '<tr valign="top">';
|
||||||
if ( !empty($field['args']['label_for']) )
|
if ( !empty($field['args']['label_for']) )
|
||||||
echo '<th scope="row"><label for="' . $field['args']['label_for'] . '">' . $field['title'] . '</label></th>';
|
echo '<th scope="row"><label for="' . esc_attr( $field['args']['label_for'] ) . '">' . $field['title'] . '</label></th>';
|
||||||
else
|
else
|
||||||
echo '<th scope="row">' . $field['title'] . '</th>';
|
echo '<th scope="row">' . $field['title'] . '</th>';
|
||||||
echo '<td>';
|
echo '<td>';
|
||||||
|
Loading…
Reference in New Issue
Block a user