From 89804fb0dbba845849cfdd42b70ff1a2330e5dc8 Mon Sep 17 00:00:00 2001
From: audrasjb
Date: Mon, 17 Oct 2022 11:04:12 +0000
Subject: [PATCH] General: Validate host on "Are you sure?" screen.
Props voldemortensen, xknown, peterwiloncc.
Built from https://develop.svn.wordpress.org/trunk@54522
git-svn-id: http://core.svn.wordpress.org/trunk@54077 1a063a9b-81f0-0310-95a4-ce76da25c4cd
---
wp-includes/functions.php | 4 +++-
wp-includes/version.php | 2 +-
2 files changed, 4 insertions(+), 2 deletions(-)
diff --git a/wp-includes/functions.php b/wp-includes/functions.php
index 56c36067bc..c303f0d4a6 100644
--- a/wp-includes/functions.php
+++ b/wp-includes/functions.php
@@ -3584,10 +3584,12 @@ function wp_nonce_ays( $action ) {
} else {
$html = __( 'The link you followed has expired.' );
if ( wp_get_referer() ) {
+ $wp_http_referer = remove_query_arg( 'updated', wp_get_referer() );
+ $wp_http_referer = wp_validate_redirect( esc_url_raw( $wp_http_referer ) );
$html .= '
';
$html .= sprintf(
'%s',
- esc_url( remove_query_arg( 'updated', wp_get_referer() ) ),
+ esc_url( $wp_http_referer ),
__( 'Please try again.' )
);
}
diff --git a/wp-includes/version.php b/wp-includes/version.php
index ad0e1dc535..e7b8ca5f6f 100644
--- a/wp-includes/version.php
+++ b/wp-includes/version.php
@@ -16,7 +16,7 @@
*
* @global string $wp_version
*/
-$wp_version = '6.1-RC1-54521';
+$wp_version = '6.1-RC1-54522';
/**
* Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.