Ticket #10041: miqro-10041-part2.patch
File miqro-10041-part2.patch, 23.9 KB (added by , 10 years ago) |
---|
-
src/wp-admin/includes/class-wp-ms-sites-list-table.php
38 38 $s = trim($s, '*'); 39 39 } 40 40 41 $like_s = esc_sql( like_escape( $s ) );42 43 41 // If the network is large and a search is not being performed, show only the latest blogs with no paging in order 44 42 // to avoid expensive count queries. 45 43 if ( !$s && wp_is_large_network() ) { … … 58 56 preg_match( '/^[0-9]{1,3}\.[0-9]{1,3}\.?$/', $s ) || 59 57 preg_match( '/^[0-9]{1,3}\.$/', $s ) ) { 60 58 // IPv4 address 61 $reg_blog_ids = $wpdb->get_col( "SELECT blog_id FROM {$wpdb->registration_log} WHERE {$wpdb->registration_log}.IP LIKE ( '{$like_s}$wild' )" ); 59 $sql = $wpdb->prepare( "SELECT blog_id FROM {$wpdb->registration_log} WHERE {$wpdb->registration_log}.IP LIKE %s", $wpdb->esc_like( $s ) . $wild ); 60 $reg_blog_ids = $wpdb->get_col( $sql ); 62 61 63 62 if ( !$reg_blog_ids ) 64 63 $reg_blog_ids = array( 0 ); … … 69 68 AND {$wpdb->blogs}.blog_id IN (" . implode( ', ', $reg_blog_ids ) . ")"; 70 69 } else { 71 70 if ( is_numeric($s) && empty( $wild ) ) { 72 $query .= " AND ( {$wpdb->blogs}.blog_id = '{$like_s}' )";71 $query .= $wpdb->prepare( " AND ( {$wpdb->blogs}.blog_id = %s )", $s ); 73 72 } elseif ( is_subdomain_install() ) { 74 $blog_s = str_replace( '.' . $current_site->domain, '', $ like_s );75 $blog_s .= $wild . '.' . $current_site->domain;76 $query .= " AND ( {$wpdb->blogs}.domain LIKE '$blog_s' ) ";73 $blog_s = str_replace( '.' . $current_site->domain, '', $s ); 74 $blog_s = $wpdb->esc_like( $blog_s ) . $wild . $wpdb->esc_like( '.' . $current_site->domain ); 75 $query .= $wpdb->prepare( " AND ( {$wpdb->blogs}.domain LIKE %s ) ", $blog_s ); 77 76 } else { 78 if ( $like_s != trim('/', $current_site->path) ) 79 $blog_s = $current_site->path . $like_s . $wild . '/'; 80 else 81 $blog_s = $like_s; 82 $query .= " AND ( {$wpdb->blogs}.path LIKE '$blog_s' )"; 77 if ( $s != trim('/', $current_site->path) ) { 78 $blog_s = $wpdb->esc_like( $current_site->path . $s ) . $wild . $wpdb->esc_like( '/' ); 79 } else { 80 $blog_s = $wpdb->esc_like( $s ); 81 } 82 $query .= $wpdb->prepare( " AND ( {$wpdb->blogs}.path LIKE %s )", $blog_s ); 83 83 } 84 84 } 85 85 -
src/wp-admin/includes/schema.php
553 553 // The multi-table delete syntax is used to delete the transient record from table a, 554 554 // and the corresponding transient_timeout record from table b. 555 555 $time = time(); 556 $wpdb->query("DELETE a, b FROM $wpdb->options a, $wpdb->options b WHERE 557 a.option_name LIKE '\_transient\_%' AND 558 a.option_name NOT LIKE '\_transient\_timeout\_%' AND 559 b.option_name = CONCAT( '_transient_timeout_', SUBSTRING( a.option_name, 12 ) ) 560 AND b.option_value < $time"); 556 $sql = "DELETE a, b FROM $wpdb->options a, $wpdb->options b 557 WHERE a.option_name LIKE %s 558 AND a.option_name NOT LIKE %s 559 AND b.option_name = CONCAT( '_transient_timeout_', SUBSTRING( a.option_name, 12 ) ) 560 AND b.option_value < %d"; 561 $wpdb->query( $wpdb->prepare( $sql, $wpdb->esc_like( '_transient_' ) . '%', $wpdb->esc_like( '_transient_timeout_' ) . '%', $time ) ); 561 562 562 563 if ( is_main_site() && is_main_network() ) { 563 $wpdb->query("DELETE a, b FROM $wpdb->options a, $wpdb->options b WHERE 564 a.option_name LIKE '\_site\_transient\_%' AND 565 a.option_name NOT LIKE '\_site\_transient\_timeout\_%' AND 566 b.option_name = CONCAT( '_site_transient_timeout_', SUBSTRING( a.option_name, 17 ) ) 567 AND b.option_value < $time"); 568 } 564 $sql = "DELETE a, b FROM $wpdb->options a, $wpdb->options b 565 WHERE a.option_name LIKE %s 566 AND a.option_name NOT LIKE %s 567 AND b.option_name = CONCAT( '_site_transient_timeout_', SUBSTRING( a.option_name, 17 ) ) 568 AND b.option_value < %d"; 569 $wpdb->query( $wpdb->prepare( $sql, $wpdb->esc_like( '_site_transient_' ) . '%', $wpdb->esc_like( '_site_transient_timeout_' ) . '%', $time ) ); 570 } 569 571 } 570 572 571 573 /** -
src/wp-admin/includes/template.php
632 632 * 633 633 * @param int $limit Number of custom fields to retrieve. Default 30. 634 634 */ 635 $limit = (int) apply_filters( 'postmeta_form_limit', 30 ); 636 $keys = $wpdb->get_col( " 637 SELECT meta_key 635 $limit = apply_filters( 'postmeta_form_limit', 30 ); 636 $sql = "SELECT meta_key 638 637 FROM $wpdb->postmeta 639 638 GROUP BY meta_key 640 HAVING meta_key NOT LIKE '\_%'639 HAVING meta_key NOT LIKE %s 641 640 ORDER BY meta_key 642 LIMIT $limit" ); 641 LIMIT %d"; 642 $keys = $wpdb->get_col( $wpdb->prepare( $sql, $wpdb->esc_like( '_' ) . '%', $limit ) ); 643 643 if ( $keys ) { 644 644 natcasesort( $keys ); 645 645 $meta_key_input_id = 'metakeyselect'; -
src/wp-admin/includes/upgrade.php
465 465 } 466 466 } 467 467 468 $wpdb->query("UPDATE $wpdb->options SET option_value = REPLACE(option_value, 'wp-links/links-images/', 'wp-images/links/') 469 WHERE option_name LIKE 'links_rating_image%' 470 AND option_value LIKE 'wp-links/links-images/%'"); 468 $sql = "UPDATE $wpdb->options 469 SET option_value = REPLACE(option_value, 'wp-links/links-images/', 'wp-images/links/') 470 WHERE option_name LIKE %s 471 AND option_value LIKE %s"; 472 $wpdb->query( $wpdb->prepare( $sql, $wpdb->esc_like( 'links_rating_image' ) . '%', $wpdb->esc_like( 'wp-links/links-images/' ) . '%' ) ); 471 473 472 474 $done_ids = $wpdb->get_results("SELECT DISTINCT post_id FROM $wpdb->post2cat"); 473 475 if ($done_ids) : … … 1100 1102 1101 1103 // 3.0 screen options key name changes. 1102 1104 if ( is_main_site() && !defined('DO_NOT_UPGRADE_GLOBAL_TABLES') ) { 1103 $prefix = like_escape($wpdb->base_prefix); 1104 $wpdb->query( "DELETE FROM $wpdb->usermeta WHERE meta_key LIKE '{$prefix}%meta-box-hidden%' OR meta_key LIKE '{$prefix}%closedpostboxes%' OR meta_key LIKE '{$prefix}%manage-%-columns-hidden%' OR meta_key LIKE '{$prefix}%meta-box-order%' OR meta_key LIKE '{$prefix}%metaboxorder%' OR meta_key LIKE '{$prefix}%screen_layout%' 1105 OR meta_key = 'manageedittagscolumnshidden' OR meta_key='managecategoriescolumnshidden' OR meta_key = 'manageedit-tagscolumnshidden' OR meta_key = 'manageeditcolumnshidden' OR meta_key = 'categories_per_page' OR meta_key = 'edit_tags_per_page'" ); 1105 $sql = "DELETE FROM $wpdb->usermeta 1106 WHERE meta_key LIKE %s 1107 OR meta_key LIKE %s 1108 OR meta_key LIKE %s 1109 OR meta_key LIKE %s 1110 OR meta_key LIKE %s 1111 OR meta_key LIKE %s 1112 OR meta_key = 'manageedittagscolumnshidden' 1113 OR meta_key = 'managecategoriescolumnshidden' 1114 OR meta_key = 'manageedit-tagscolumnshidden' 1115 OR meta_key = 'manageeditcolumnshidden' 1116 OR meta_key = 'categories_per_page' 1117 OR meta_key = 'edit_tags_per_page'"; 1118 $prefix = $wpdb->esc_like( $wpdb->base_prefix ); 1119 $wpdb->query( $wpdb->prepare( $sql, 1120 $prefix . '%' . $wpdb->esc_like( 'meta-box-hidden' ) . '%', 1121 $prefix . '%' . $wpdb->esc_like( 'closedpostboxes' ) . '%', 1122 $prefix . '%' . $wpdb->esc_like( 'manage-' ) . '%' . $wpdb->esc_like( '-columns-hidden' ) . '%', 1123 $prefix . '%' . $wpdb->esc_like( 'meta-box-order' ) . '%', 1124 $prefix . '%' . $wpdb->esc_like( 'metaboxorder' ) . '%', 1125 $prefix . '%' . $wpdb->esc_like( 'screen_layout' ) . '%' 1126 ) ); 1106 1127 } 1107 1128 1108 1129 } … … 1284 1305 // The multi-table delete syntax is used to delete the transient record from table a, 1285 1306 // and the corresponding transient_timeout record from table b. 1286 1307 $time = time(); 1287 $wpdb->query("DELETE a, b FROM $wpdb->sitemeta a, $wpdb->sitemeta b WHERE 1288 a.meta_key LIKE '\_site\_transient\_%' AND 1289 a.meta_key NOT LIKE '\_site\_transient\_timeout\_%' AND 1290 b.meta_key = CONCAT( '_site_transient_timeout_', SUBSTRING( a.meta_key, 17 ) ) 1291 AND b.meta_value < $time"); 1308 $sql = "DELETE a, b FROM $wpdb->sitemeta a, $wpdb->sitemeta b 1309 WHERE a.meta_key LIKE %s 1310 AND a.meta_key NOT LIKE %s 1311 AND b.meta_key = CONCAT( '_site_transient_timeout_', SUBSTRING( a.meta_key, 17 ) ) 1312 AND b.meta_value < %d"; 1313 $wpdb->query( $wpdb->prepare( $sql, $wpdb->esc_like( '_site_transient_' ) . '%', $wpdb->esc_like ( '_site_transient_timeout_' ) . '%', $time ) ); 1292 1314 } 1293 1315 1294 1316 // 2.8 … … 1382 1404 */ 1383 1405 function maybe_create_table($table_name, $create_ddl) { 1384 1406 global $wpdb; 1385 if ( $wpdb->get_var("SHOW TABLES LIKE '$table_name'") == $table_name ) 1407 1408 $query = $wpdb->prepare( "SHOW TABLES LIKE %s", $wpdb->esc_like( $table_name ) ); 1409 1410 if ( $wpdb->get_var( $query ) == $table_name ) { 1386 1411 return true; 1412 } 1387 1413 //didn't find it try to create it. 1388 1414 $wpdb->query($create_ddl); 1389 1415 // we cannot directly tell that whether this succeeded! 1390 if ( $wpdb->get_var( "SHOW TABLES LIKE '$table_name'") == $table_name )1416 if ( $wpdb->get_var( $query ) == $table_name ) { 1391 1417 return true; 1418 } 1392 1419 return false; 1393 1420 } 1394 1421 -
src/wp-admin/install.php
74 74 */ 75 75 function display_setup_form( $error = null ) { 76 76 global $wpdb; 77 $user_table = ( $wpdb->get_var("SHOW TABLES LIKE '$wpdb->users'") != null );78 77 78 $sql = $wpdb->prepare( "SHOW TABLES LIKE %s", $wpdb->esc_like( $wpdb->users ) ); 79 $user_table = ( $wpdb->get_var( $sql ) != null ); 80 79 81 // Ensure that Blogs appear in search engines by default 80 82 $blog_public = 1; 81 83 if ( ! empty( $_POST ) ) -
src/wp-admin/maint/repair.php
36 36 $tables = $wpdb->tables(); 37 37 38 38 // Sitecategories may not exist if global terms are disabled. 39 if ( is_multisite() && ! $wpdb->get_var( "SHOW TABLES LIKE '$wpdb->sitecategories'" ) ) 39 $query = $wpdb->prepare( "SHOW TABLES LIKE %s", $wpdb->esc_like( $wpdb->sitecategories ) ); 40 if ( is_multisite() && ! $wpdb->get_var( $query ) ) { 40 41 unset( $tables['sitecategories'] ); 42 } 41 43 42 44 /** 43 45 * Filter additional database tables to repair. -
src/wp-admin/network.php
39 39 */ 40 40 function network_domain_check() { 41 41 global $wpdb; 42 if ( $wpdb->get_var( "SHOW TABLES LIKE '$wpdb->site'" ) ) 42 43 $sql = $wpdb->prepare( "SHOW TABLES LIKE %s", $wpdb->esc_like( $wpdb->site ) ); 44 if ( $wpdb->get_var( $sql ) ) { 43 45 return $wpdb->get_var( "SELECT domain FROM $wpdb->site ORDER BY id ASC LIMIT 1" ); 46 } 44 47 return false; 45 48 } 46 49 -
src/wp-admin/network/site-settings.php
113 113 <table class="form-table"> 114 114 <?php 115 115 $blog_prefix = $wpdb->get_blog_prefix( $id ); 116 $options = $wpdb->get_results( "SELECT * FROM {$blog_prefix}options WHERE option_name NOT LIKE '\_%' AND option_name NOT LIKE '%user_roles'" ); 116 $sql = "SELECT * FROM {$blog_prefix}options 117 WHERE option_name NOT LIKE %s 118 AND option_name NOT LIKE %s"; 119 $query = $wpdb->prepare( $sql, 120 $wpdb->esc_like( '_' ) . '%', 121 '%' . $wpdb->esc_like( 'user_roles' ) 122 ); 123 $options = $wpdb->get_results( $query ); 117 124 foreach ( $options as $option ) { 118 125 if ( $option->option_name == 'default_role' ) 119 126 $editblog_default_role = $option->option_value; -
src/wp-includes/bookmark.php
208 208 209 209 $search = ''; 210 210 if ( ! empty( $r['search'] ) ) { 211 $ search = esc_sql( like_escape( $r['search'] ) );212 $search = " AND ( (link_url LIKE '%$search%') OR (link_name LIKE '%$search%') OR (link_description LIKE '%$search%') ) ";211 $like = '%' . $wpdb->esc_like( $r['search'] ) . '%'; 212 $search = $wpdb->prepare(" AND ( (link_url LIKE %s) OR (link_name LIKE %s) OR (link_description LIKE %s) ) ", $like, $like, $like ); 213 213 } 214 214 215 215 $category_query = ''; -
src/wp-includes/canonical.php
504 504 global $wpdb, $wp_rewrite; 505 505 506 506 if ( get_query_var('name') ) { 507 $where = $wpdb->prepare("post_name LIKE %s", like_escape( get_query_var('name') ) . '%');507 $where = $wpdb->prepare("post_name LIKE %s", $wpdb->esc_like( get_query_var('name') ) . '%'); 508 508 509 509 // if any of post_type, year, monthnum, or day are set, use them to refine the query 510 510 if ( get_query_var('post_type') ) -
src/wp-includes/class-wp-xmlrpc-server.php
5764 5764 } elseif ( is_string($urltest['fragment']) ) { 5765 5765 // ...or a string #title, a little more complicated 5766 5766 $title = preg_replace('/[^a-z0-9]/i', '.', $urltest['fragment']); 5767 $sql = $wpdb->prepare("SELECT ID FROM $wpdb->posts WHERE post_title RLIKE %s", like_escape( $title ));5767 $sql = $wpdb->prepare("SELECT ID FROM $wpdb->posts WHERE post_title RLIKE %s", $title ); 5768 5768 if (! ($post_ID = $wpdb->get_var($sql)) ) { 5769 5769 // returning unknown error '0' is better than die()ing 5770 5770 return $this->pingback_error( 0, '' ); -
src/wp-includes/comment.php
481 481 * @return string 482 482 */ 483 483 protected function get_search_sql( $string, $cols ) { 484 $string = esc_sql( like_escape( $string ) );484 global $wpdb; 485 485 486 486 $searches = array(); 487 487 foreach ( $cols as $col ) 488 $searches[] = "$col LIKE '%$string%'";488 $searches[] = $wpdb->prepare( "$col LIKE %s", $wpdb->esc_like( $string ) ); 489 489 490 490 return ' AND (' . implode(' OR ', $searches) . ')'; 491 491 } -
src/wp-includes/functions.php
479 479 480 480 foreach ( $pung as $link_test ) { 481 481 if ( ! in_array( $link_test, $post_links_temp ) ) { // link no longer in post 482 $mids = $wpdb->get_col( $wpdb->prepare("SELECT meta_id FROM $wpdb->postmeta WHERE post_id = %d AND meta_key = 'enclosure' AND meta_value LIKE (%s)", $post_ID, like_escape( $link_test ) . '%') );482 $mids = $wpdb->get_col( $wpdb->prepare("SELECT meta_id FROM $wpdb->postmeta WHERE post_id = %d AND meta_key = 'enclosure' AND meta_value LIKE %s", $post_ID, $wpdb->esc_like( $link_test ) . '%') ); 483 483 foreach ( $mids as $mid ) 484 484 delete_metadata_by_mid( 'post', $mid ); 485 485 } … … 498 498 } 499 499 500 500 foreach ( (array) $post_links as $url ) { 501 if ( $url != '' && !$wpdb->get_var( $wpdb->prepare( "SELECT post_id FROM $wpdb->postmeta WHERE post_id = %d AND meta_key = 'enclosure' AND meta_value LIKE (%s)", $post_ID, like_escape( $url ) . '%' ) ) ) {501 if ( $url != '' && !$wpdb->get_var( $wpdb->prepare( "SELECT post_id FROM $wpdb->postmeta WHERE post_id = %d AND meta_key = 'enclosure' AND meta_value LIKE %s", $post_ID, $wpdb->esc_like( $url ) . '%' ) ) ) { 502 502 503 503 if ( $headers = wp_get_http_headers( $url) ) { 504 504 $len = isset( $headers['content-length'] ) ? (int) $headers['content-length'] : 0; -
src/wp-includes/meta.php
1047 1047 } elseif ( 'BETWEEN' == substr( $meta_compare, -7) ) { 1048 1048 $meta_value = array_slice( $meta_value, 0, 2 ); 1049 1049 $meta_compare_string = '%s AND %s'; 1050 } elseif ( 'LIKE' == substr( $meta_compare, -4) ) {1051 $meta_value = '%' . like_escape( $meta_value ) . '%';1050 } elseif ( 'LIKE' == $meta_compare || 'NOT LIKE' == $meta_compare ) ) { 1051 $meta_value = '%' . $wpdb->esc_like( $meta_value ) . '%'; 1052 1052 $meta_compare_string = '%s'; 1053 1053 } else { 1054 1054 $meta_compare_string = '%s'; -
src/wp-includes/ms-load.php
397 397 398 398 $title = __( 'Error establishing a database connection' ); 399 399 $msg = '<h1>' . $title . '</h1>'; 400 if ( ! is_admin() ) 400 if ( ! is_admin() ) { 401 401 die( $msg ); 402 } 402 403 $msg .= '<p>' . __( 'If your site does not display, please contact the owner of this network.' ) . ''; 403 404 $msg .= ' ' . __( 'If you are the owner of this network please check that MySQL is running properly and all tables are error free.' ) . '</p>'; 404 if ( ! $wpdb->get_var( "SHOW TABLES LIKE '$wpdb->site'" ) ) 405 $query = $wpdb->prepare( "SHOW TABLES LIKE %s", $wpdb->esc_like( $wpdb->site ) ); 406 if ( ! $wpdb->get_var( $query ) ) { 405 407 $msg .= '<p>' . sprintf( __( '<strong>Database tables are missing.</strong> This means that MySQL is not running, WordPress was not installed properly, or someone deleted <code>%s</code>. You really should look at your database now.' ), $wpdb->site ) . '</p>'; 406 else408 } else { 407 409 $msg .= '<p>' . sprintf( __( '<strong>Could not find site <code>%1$s</code>.</strong> Searched for table <code>%2$s</code> in database <code>%3$s</code>. Is that right?' ), rtrim( $domain . $path, '/' ), $wpdb->blogs, DB_NAME ) . '</p>'; 410 } 408 411 $msg .= '<p><strong>' . __( 'What do I do now?' ) . '</strong> '; 409 412 $msg .= __( 'Read the <a target="_blank" href="http://codex.wordpress.org/Debugging_a_WordPress_Network">bug report</a> page. Some of the guidelines there may help you figure out what went wrong.' ); 410 413 $msg .= ' ' . __( 'If you’re still stuck with this message, then check that your database contains the following tables:' ) . '</p><ul>'; -
src/wp-includes/post.php
4796 4796 4797 4797 if ( ! empty($meta['thumb']) ) { 4798 4798 // Don't delete the thumb if another attachment uses it 4799 if (! $wpdb->get_row( $wpdb->prepare( "SELECT meta_id FROM $wpdb->postmeta WHERE meta_key = '_wp_attachment_metadata' AND meta_value LIKE %s AND post_id <> %d", '%' . $ meta['thumb']. '%', $post_id)) ) {4799 if (! $wpdb->get_row( $wpdb->prepare( "SELECT meta_id FROM $wpdb->postmeta WHERE meta_key = '_wp_attachment_metadata' AND meta_value LIKE %s AND post_id <> %d", '%' . $wpdb->esc_like( $meta['thumb'] ) . '%', $post_id)) ) { 4800 4800 $thumbfile = str_replace(basename($file), $meta['thumb'], $file); 4801 4801 /** This filter is documented in wp-admin/custom-header.php */ 4802 4802 $thumbfile = apply_filters( 'wp_delete_file', $thumbfile ); -
src/wp-includes/query.php
1983 1983 $searchand = ''; 1984 1984 $q['search_orderby_title'] = array(); 1985 1985 foreach ( $q['search_terms'] as $term ) { 1986 $term = like_escape( esc_sql( $term ) ); 1987 if ( $n ) 1988 $q['search_orderby_title'][] = "$wpdb->posts.post_title LIKE '%$term%'"; 1986 if ( $n ) { 1987 $like = '%' . $wpdb->esc_like( $term ) . '%'; 1988 $q['search_orderby_title'][] = $wpdb->prepare( "$wpdb->posts.post_title LIKE %s", $like ); 1989 } 1989 1990 1990 $search .= "{$searchand}(($wpdb->posts.post_title LIKE '{$n}{$term}{$n}') OR ($wpdb->posts.post_content LIKE '{$n}{$term}{$n}'))"; 1991 $like = $n . $wpdb->esc_like( $term ) . $n; 1992 $search .= $wpdb->prepare( "{$searchand}(($wpdb->posts.post_title LIKE %s) OR ($wpdb->posts.post_content LIKE %s))", $like, $like ); 1991 1993 $searchand = ' AND '; 1992 1994 } 1993 1995 … … 2086 2088 2087 2089 if ( $q['search_terms_count'] > 1 ) { 2088 2090 $num_terms = count( $q['search_orderby_title'] ); 2089 $ search_orderby_s = like_escape( esc_sql( $q['s'] ) );2091 $like = '%' . $wpdb->esc_like( $q['s'] ) . '%'; 2090 2092 2091 2093 $search_orderby = '(CASE '; 2092 2094 // sentence match in 'post_title' 2093 $search_orderby .= "WHEN $wpdb->posts.post_title LIKE '%{$search_orderby_s}%' THEN 1 ";2095 $search_orderby .= $wpdb->prepare( "WHEN $wpdb->posts.post_title LIKE %s THEN 1 ", $like ); 2094 2096 2095 2097 // sanity limit, sort as sentence when more than 6 terms 2096 2098 // (few searches are longer than 6 terms and most titles are not) … … 2103 2105 } 2104 2106 2105 2107 // sentence match in 'post_content' 2106 $search_orderby .= "WHEN $wpdb->posts.post_content LIKE '%{$search_orderby_s}%' THEN 4 ";2108 $search_orderby .= $wpdb->prepare( "WHEN $wpdb->posts.post_content LIKE %s THEN 4 ", $like ); 2107 2109 $search_orderby .= 'ELSE 5 END)'; 2108 2110 } else { 2109 2111 // single word or sentence search -
src/wp-includes/taxonomy.php
1480 1480 } 1481 1481 1482 1482 if ( ! empty( $args['name__like'] ) ) { 1483 $name__like = like_escape( $args['name__like'] ); 1484 $where .= $wpdb->prepare( " AND t.name LIKE %s", '%' . $name__like . '%' ); 1483 $where .= $wpdb->prepare( " AND t.name LIKE %s", '%' . $wpdb->esc_like( $args['name__like'] ) . '%' ); 1485 1484 } 1486 1485 1487 1486 if ( ! empty( $args['description__like'] ) ) { 1488 $description__like = like_escape( $args['description__like'] ); 1489 $where .= $wpdb->prepare( " AND tt.description LIKE %s", '%' . $description__like . '%' ); 1487 $where .= $wpdb->prepare( " AND tt.description LIKE %s", '%' . $wpdb->esc_like( $args['description__like'] ) . '%' ); 1490 1488 } 1491 1489 1492 1490 if ( '' !== $parent ) { … … 1517 1515 } 1518 1516 1519 1517 if ( ! empty( $args['search'] ) ) { 1520 $ search = like_escape( $args['search'] );1521 $where .= $wpdb->prepare( ' AND ((t.name LIKE %s) OR (t.slug LIKE %s))', '%' . $search . '%', '%' . $search . '%');1518 $like = '%' . $wpdb->esc_like( $args['search'] ) . '%'; 1519 $where .= $wpdb->prepare( ' AND ((t.name LIKE %s) OR (t.slug LIKE %s))', $like, $like ); 1522 1520 } 1523 1521 1524 1522 $selects = array(); -
src/wp-includes/user.php
797 797 * @return string 798 798 */ 799 799 protected function get_search_sql( $string, $cols, $wild = false ) { 800 $string = esc_sql( $string );800 global $wpdb; 801 801 802 802 $searches = array(); 803 803 $leading_wild = ( 'leading' == $wild || 'both' == $wild ) ? '%' : ''; … … 804 804 $trailing_wild = ( 'trailing' == $wild || 'both' == $wild ) ? '%' : ''; 805 805 foreach ( $cols as $col ) { 806 806 if ( 'ID' == $col ) 807 $searches[] = "$col = '$string'";807 $searches[] = $wpdb->prepare( "$col = %s", $string ); 808 808 else 809 $searches[] = "$col LIKE '$leading_wild" . like_escape($string) . "$trailing_wild'";809 $searches[] = $wpdb->prepare( "$col LIKE %s", $leading_wild . $wpdb->esc_like( $string ) . $trailing_wild ); 810 810 } 811 811 812 812 return ' AND (' . implode(' OR ', $searches) . ')'; … … 1149 1149 // Build a CPU-intensive query that will return concise information. 1150 1150 $select_count = array(); 1151 1151 foreach ( $avail_roles as $this_role => $name ) { 1152 $select_count[] = "COUNT(NULLIF(`meta_value` LIKE '%\"" . like_escape( $this_role ) . "\"%', false))";1152 $select_count[] = $wpdb->prepare( "COUNT(NULLIF(`meta_value` LIKE %s, false))", '%' . $wpdb->esc_like( '"' . $this_role . '"' ) . '%'); 1153 1153 } 1154 1154 $select_count = implode(', ', $select_count); 1155 1155