Make WordPress Core

Ticket #21523: 21523.5.patch

File 21523.5.patch, 4.3 KB (added by obenland, 9 years ago)
  • src/wp-admin/credits.php

     
    6969 * @param string &$data External library data, passed by reference.
    7070 */
    7171function _wp_credits_build_object_link( &$data ) {
    72         $data = '<a href="' . esc_url( $data[1] ) . '">' . $data[0] . '</a>';
     72        $data = '<a href="' . esc_url( $data[1] ) . '">' . esc_html( $data[0] ) . '</a>';
    7373}
    7474
    7575list( $display_version ) = explode( '-', $wp_version );
     
    7878?>
    7979<div class="wrap about-wrap">
    8080
    81 <h1><?php printf( __( 'Welcome to WordPress %s' ), $display_version ); ?></h1>
     81<h1><?php printf( __( 'Welcome to WordPress %s' ), esc_html( $display_version ) ); ?></h1>
    8282
    83 <div class="about-text"><?php printf( __( 'Thank you for updating! WordPress %s helps you communicate and share, globally.' ), $display_version ); ?></div>
     83<div class="about-text"><?php printf( __( 'Thank you for updating! WordPress %s helps you communicate and share, globally.' ), esc_html( $display_version ) ); ?></div>
    8484
    85 <div class="wp-badge"><?php printf( __( 'Version %s' ), $display_version ); ?></div>
     85<div class="wp-badge"><?php printf( __( 'Version %s' ), esc_html( $display_version ) ); ?></div>
    8686
    8787<h2 class="nav-tab-wrapper">
    8888        <a href="about.php" class="nav-tab">
     
    9999$credits = wp_credits();
    100100
    101101if ( ! $credits ) {
    102         echo '<p class="about-description">' . sprintf( __( 'WordPress is created by a <a href="%1$s">worldwide team</a> of passionate individuals. <a href="%2$s">Get involved in WordPress</a>.' ),
     102        echo '<p class="about-description">' . esc_html( sprintf( __( 'WordPress is created by a <a href="%1$s">worldwide team</a> of passionate individuals. <a href="%2$s">Get involved in WordPress</a>.' ),
    103103                'https://wordpress.org/about/',
    104104                /* translators: Url to the codex documentation on contributing to WordPress used on the credits page */
    105                 __( 'https://codex.wordpress.org/Contributing_to_WordPress' ) ) . '</p>';
     105                __( 'https://codex.wordpress.org/Contributing_to_WordPress' ) ) ) . '</p>';
    106106        include( ABSPATH . 'wp-admin/admin-footer.php' );
    107107        exit;
    108108}
     
    120120                        $title = translate( $group_data['name'] );
    121121                }
    122122
    123                 echo '<h4 class="wp-people-group">' . $title . "</h4>\n";
     123                echo '<h4 class="wp-people-group">' . esc_html( $title ) . "</h4>\n";
    124124        }
    125125
    126126        if ( ! empty( $group_data['shuffle'] ) )
     
    138138                default:
    139139                        $compact = 'compact' == $group_data['type'];
    140140                        $classes = 'wp-people-group ' . ( $compact ? 'compact' : '' );
    141                         echo '<ul class="' . $classes . '" id="wp-people-group-' . $group_slug . '">' . "\n";
     141                        echo '<ul class="' . esc_attr( $classes ) . '" id="wp-people-group-' . $group_slug . '">' . "\n";
    142142                        foreach ( $group_data['data'] as $person_data ) {
    143                                 echo '<li class="wp-person" id="wp-person-' . $person_data[2] . '">' . "\n\t";
    144                                 echo '<a href="' . sprintf( $credits['data']['profiles'], $person_data[2] ) . '">';
     143                                echo '<li class="wp-person" id="wp-person-' . esc_attr( $person_data[2] ) . '">' . "\n\t";
     144                                echo '<a href="' . esc_url( sprintf( $credits['data']['profiles'], $person_data[2] ) ) . '">';
    145145                                $size = 'compact' == $group_data['type'] ? 30 : 60;
    146146                                $data = get_avatar_data( $person_data[1] . '@md5.gravatar.com', array( 'size' => $size ) );
    147147                                $size *= 2;
    148148                                $data2x = get_avatar_data( $person_data[1] . '@md5.gravatar.com', array( 'size' => $size ) );
    149                                 echo '<img src="' . esc_attr( $data['url'] ) . '" srcset="' . esc_attr( $data2x['url'] ) . ' 2x" class="gravatar" alt="' . esc_attr( $person_data[0] ) . '" /></a>' . "\n\t";
    150                                 echo '<a class="web" href="' . sprintf( $credits['data']['profiles'], $person_data[2] ) . '">' . $person_data[0] . "</a>\n\t";
     149                                echo '<img src="' . esc_url( $data['url'] ) . '" srcset="' . esc_attr( $data2x['url'] ) . ' 2x" class="gravatar" alt="' . esc_attr( $person_data[0] ) . '" /></a>' . "\n\t";
     150                                echo '<a class="web" href="' . esc_url( sprintf( $credits['data']['profiles'], $person_data[2] ) ) . '">' . esc_html( $person_data[0] ) . "</a>\n\t";
    151151                                if ( ! $compact )
    152                                         echo '<span class="title">' . translate( $person_data[3] ) . "</span>\n";
     152                                        echo '<span class="title">' . esc_html( translate( $person_data[3] ) ) . "</span>\n";
    153153                                echo "</li>\n";
    154154                        }
    155155                        echo "</ul>\n";