Quotes in post title make it into the title for comments_popup_link()
|Reported by:||Viper007Bond||Owned by:||markjaquith|
If you have a post with quotes in it, they make it into the title for the comments_popup_link() link. This makes invalid code.
Post title = Announcing "Alphabetical Plugins"
Then this code:
comments_popup_link('Comments Off', '1 Comment »', '% Comments »');
<a href="http://www.viper007bond.com/archives/2005/11/27/announcing-alphabetical-plugins/#respond" title="Comment on Announcing "Alphabetical Plugins"">Comments Off</a>
Solution: htmlspecialchars() or wp_texturize() needs to be run on the post title before it's used.
Change History (13)
- Keywords bg|commit added
- Milestone set to 2.1
- Owner changed from anonymous to markjaquith
- Status changed from new to assigned