WordPress.org

Make WordPress Core

Ticket #22326: 22326.patch

File 22326.patch, 1.2 KB (added by johnjamesjacoby, 6 years ago)
  • wp-admin/includes/misc.php

     
    537537if ( empty($current_color) )
    538538        $current_color = 'fresh';
    539539foreach ( $_wp_admin_css_colors as $color => $color_info ): ?>
    540 <div class="color-option"><input name="admin_color" id="admin_color_<?php echo $color; ?>" type="radio" value="<?php echo esc_attr($color) ?>" class="tog" <?php checked($color, $current_color); ?> />
     540<div class="color-option"><input name="admin_color" id="admin_color_<?php echo esc_attr( $color ); ?>" type="radio" value="<?php echo esc_attr( $color ); ?>" class="tog" <?php checked($color, $current_color); ?> />
    541541        <table class="color-palette">
    542542        <tr>
    543543        <?php foreach ( $color_info->colors as $html_color ): ?>
    544         <td style="background-color: <?php echo $html_color ?>" title="<?php echo $color ?>">&nbsp;</td>
     544        <td style="background-color: <?php echo esc_attr( $html_color ); ?>" title="<?php echo esc_attr( $color ); ?>">&nbsp;</td>
    545545        <?php endforeach; ?>
    546546        </tr>
    547547        </table>
    548548
    549         <label for="admin_color_<?php echo $color; ?>"><?php echo $color_info->name ?></label>
     549        <label for="admin_color_<?php echo esc_attr( $color ); ?>"><?php echo esc_html( $color_info->name ); ?></label>
    550550</div>
    551551        <?php endforeach; ?>
    552552</fieldset>