new file mode 100644
---wp-includes/class-simplepie-kses.php (revision 0)n+++wp-includes/class-simplepie-kses.php (revision 0)
@@ -0,0 +1,27 @@
+<?php
+/**
+ * WordPress extension of SimplePie sanitization
+ *
+ * Contains the WP_SimplePie_Sanitize_KSES class
+ *
+ * @package WordPress
+ */
+
+/**
+ * WordPress SimplePie Sanitization Class
+ *
+ * Extension of the SimplePie_Sanitize class to use KSES, because
+ * we cannot universally count on DOMDocument being available
+ *
+ * @package WordPress
+ * @since 3.5.0
+ */
+class WP_SimplePie_Sanitize_KSES extends SimplePie_Sanitize {
+ public function sanitize( $data, $type, $base = '' ) {
+ if ( $type & ( SIMPLEPIE_CONSTRUCT_HTML | SIMPLEPIE_CONSTRUCT_XHTML ) ) {
+ return wp_kses_post( $data );
+ } else {
+ return parent::sanitize( $data, $type, $base );
+ }
+ }
+}
|
|
function feed_content_type( $type = '' ) { |
525 | 525 | */ |
526 | 526 | function fetch_feed($url) { |
527 | 527 | require_once (ABSPATH . WPINC . '/class-feed.php'); |
| 528 | require_once (ABSPATH . WPINC . '/class-simplepie-kses.php'); |
528 | 529 | |
529 | 530 | $feed = new SimplePie(); |
530 | 531 | |
| 532 | $feed->set_sanitize_class( 'WP_SimplePie_Sanitize_KSES' ); |
| 533 | // We must manually overwrite $feed->sanitize because SimplePie's |
| 534 | // constructor sets it before we have a chance to set the sanitization class |
| 535 | $feed->sanitize = new WP_SimplePie_Sanitize_KSES(); |
| 536 | |
531 | 537 | $feed->set_cache_class( 'WP_Feed_Cache' ); |
532 | 538 | $feed->set_file_class( 'WP_SimplePie_File' ); |
533 | 539 | |