From feda17a63cc7f25a60032f930fa50339379a8367 Mon Sep 17 00:00:00 2001 From: desrosj Date: Wed, 4 Sep 2019 21:40:56 +0000 Subject: [PATCH] Fix for URL sanitization in `wp_kses_bad_protocol_once()`. Merges [45997] to the 4.4 branch. Props irsdl, sstoqnov, whyisjake. Built from https://develop.svn.wordpress.org/branches/4.4@46010 git-svn-id: http://core.svn.wordpress.org/branches/4.4@45821 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-includes/kses.php | 1 + 1 file changed, 1 insertion(+) diff --git a/wp-includes/kses.php b/wp-includes/kses.php index bb0ad614d7..3d3b9fff25 100644 --- a/wp-includes/kses.php +++ b/wp-includes/kses.php @@ -1395,6 +1395,7 @@ function wp_kses_html_error($string) { * @return string Sanitized content */ function wp_kses_bad_protocol_once($string, $allowed_protocols, $count = 1 ) { + $string = preg_replace( '/(�*58(?![;0-9])|�*3a(?![;a-f0-9]))/i', '$1;', $string ); $string2 = preg_split( '/:|�*58;|�*3a;/i', $string, 2 ); if ( isset($string2[1]) && ! preg_match('%/\?%', $string2[0]) ) { $string = trim( $string2[1] );