WordPress.org

Make WordPress Core

Ticket #22326: 22326.patch

File 22326.patch, 1.2 KB (added by johnjamesjacoby, 18 months ago)
  • wp-admin/includes/misc.php

     
    537537if ( empty($current_color) ) 
    538538        $current_color = 'fresh'; 
    539539foreach ( $_wp_admin_css_colors as $color => $color_info ): ?> 
    540 <div class="color-option"><input name="admin_color" id="admin_color_<?php echo $color; ?>" type="radio" value="<?php echo esc_attr($color) ?>" class="tog" <?php checked($color, $current_color); ?> /> 
     540<div class="color-option"><input name="admin_color" id="admin_color_<?php echo esc_attr( $color ); ?>" type="radio" value="<?php echo esc_attr( $color ); ?>" class="tog" <?php checked($color, $current_color); ?> /> 
    541541        <table class="color-palette"> 
    542542        <tr> 
    543543        <?php foreach ( $color_info->colors as $html_color ): ?> 
    544         <td style="background-color: <?php echo $html_color ?>" title="<?php echo $color ?>">&nbsp;</td> 
     544        <td style="background-color: <?php echo esc_attr( $html_color ); ?>" title="<?php echo esc_attr( $color ); ?>">&nbsp;</td> 
    545545        <?php endforeach; ?> 
    546546        </tr> 
    547547        </table> 
    548548 
    549         <label for="admin_color_<?php echo $color; ?>"><?php echo $color_info->name ?></label> 
     549        <label for="admin_color_<?php echo esc_attr( $color ); ?>"><?php echo esc_html( $color_info->name ); ?></label> 
    550550</div> 
    551551        <?php endforeach; ?> 
    552552</fieldset>