diff --git a/src/wp-trackback.php b/src/wp-trackback.php
index 7512e33fb4..569870f220 100644
a
|
b
|
$trackback_url = isset( $_POST['url'] ) ? $_POST['url'] : ''; |
54 | 54 | $charset = isset( $_POST['charset'] ) ? $_POST['charset'] : ''; |
55 | 55 | |
56 | 56 | // These three are stripslashed here so they can be properly escaped after mb_convert_encoding(). |
57 | | $title = isset( $_POST['title'] ) ? wp_unslash( $_POST['title'] ) : ''; |
58 | | $excerpt = isset( $_POST['excerpt'] ) ? wp_unslash( $_POST['excerpt'] ) : ''; |
59 | | $blog_name = isset( $_POST['blog_name'] ) ? wp_unslash( $_POST['blog_name'] ) : ''; |
| 57 | $title = isset( $_POST['title'] ) ? sanitize_text_field( wp_unslash( $_POST['title'] ) ) : ''; |
| 58 | $excerpt = isset( $_POST['excerpt'] ) ? sanitize_textarea_field( wp_unslash( $_POST['excerpt'] ) ) : ''; |
| 59 | $blog_name = isset( $_POST['blog_name'] ) ? sanitize_text_field( wp_unslash( $_POST['blog_name'] ) ) : ''; |
60 | 60 | |
61 | 61 | if ( $charset ) { |
62 | 62 | $charset = str_replace( array( ',', ' ' ), '', strtoupper( trim( $charset ) ) ); |