Make WordPress Core

Ticket #58831: 58831-add-missing-escape-wp-admin-plugins.patch

File 58831-add-missing-escape-wp-admin-plugins.patch, 433 bytes (added by viralsampat, 4 months ago)
  • src/wp-admin/plugins.php

    diff --git src/wp-admin/plugins.php src/wp-admin/plugins.php
    index 164467952f..3c7dc9cdb2 100644
    if ( isset( $_GET['error'] ) ) : 
    640640        }
    641641
    642642        ?>
    643         <div id="message" class="error"><p><?php echo $errmsg; ?></p>
     643        <div id="message" class="error"><p><?php echo esc_html( $errmsg ); ?></p>
    644644        <?php
    645645
    646646        if ( ! isset( $_GET['main'] ) && ! isset( $_GET['charsout'] )