From b4a86c0f507ec45bb45f99814f4fad5b5eb66e40 Mon Sep 17 00:00:00 2001 From: Konstantin Obenland Date: Wed, 1 Jul 2015 17:22:24 +0000 Subject: [PATCH] Add additional escaping to credits page. Props Viper007Bond, gtuk for initial patch. Fixes #21523. Built from https://develop.svn.wordpress.org/trunk@33032 git-svn-id: http://core.svn.wordpress.org/trunk@33003 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-admin/credits.php | 12 ++++++------ wp-includes/version.php | 2 +- 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/wp-admin/credits.php b/wp-admin/credits.php index 9cc4544c29..aaa5a4a2fa 100644 --- a/wp-admin/credits.php +++ b/wp-admin/credits.php @@ -69,7 +69,7 @@ function _wp_credits_add_profile_link( &$display_name, $username, $profiles ) { * @param string &$data External library data, passed by reference. */ function _wp_credits_build_object_link( &$data ) { - $data = '' . $data[0] . ''; + $data = '' . esc_html( $data[0] ) . ''; } list( $display_version ) = explode( '-', $wp_version ); @@ -120,7 +120,7 @@ foreach ( $credits['groups'] as $group_slug => $group_data ) { $title = translate( $group_data['name'] ); } - echo '

' . $title . "

\n"; + echo '

' . esc_html( $title ) . "

\n"; } if ( ! empty( $group_data['shuffle'] ) ) @@ -140,14 +140,14 @@ foreach ( $credits['groups'] as $group_slug => $group_data ) { $classes = 'wp-people-group ' . ( $compact ? 'compact' : '' ); echo '