Make WordPress Core

Ticket #56064: 56064.patch

File 56064.patch, 1.2 KB (added by smit08, 2 years ago)
  • src/wp-admin/includes/media.php

     
    145145        }
    146146
    147147        if ( $url ) {
    148                 $html = '<a href="' . esc_attr( $url ) . '"' . $rel . '>' . $html . '</a>';
     148                $html = '<a href="' . esc_url( $url ) . '"' . $rel . '>' . $html . '</a>';
    149149        }
    150150
    151151        /**
     
    12691269        return "
    12701270        <input type='text' class='text urlfield' name='attachments[$post->ID][url]' value='" . esc_attr( $url ) . "' /><br />
    12711271        <button type='button' class='button urlnone' data-link-url=''>" . __( 'None' ) . "</button>
    1272         <button type='button' class='button urlfile' data-link-url='" . esc_attr( $file ) . "'>" . __( 'File URL' ) . "</button>
    1273         <button type='button' class='button urlpost' data-link-url='" . esc_attr( $link ) . "'>" . __( 'Attachment Post URL' ) . '</button>
     1272        <button type='button' class='button urlfile' data-link-url='" . esc_url( $file ) . "'>" . __( 'File URL' ) . "</button>
     1273        <button type='button' class='button urlpost' data-link-url='" . esc_url( $link ) . "'>" . __( 'Attachment Post URL' ) . '</button>
    12741274';
    12751275}
    12761276