diff --git src/wp-admin/includes/class-wp-screen.php src/wp-admin/includes/class-wp-screen.php
index 739a182ded..c8aa2ccbc4 100644
|
|
final class WP_Screen { |
882 | 882 | $panel_id = "tab-panel-{$tab['id']}"; |
883 | 883 | ?> |
884 | 884 | |
885 | | <li id="<?php echo esc_attr( $link_id ); ?>"<?php echo $class; ?>> |
| 885 | <li id="<?php echo esc_attr( $link_id ); ?>"<?php echo esc_attr( $class ); ?>> |
886 | 886 | <a href="<?php echo esc_url( "#$panel_id" ); ?>" aria-controls="<?php echo esc_attr( $panel_id ); ?>"> |
887 | 887 | <?php echo esc_html( $tab['title'] ); ?> |
888 | 888 | </a> |
… |
… |
final class WP_Screen { |
896 | 896 | |
897 | 897 | <?php if ( $help_sidebar ) : ?> |
898 | 898 | <div class="contextual-help-sidebar"> |
899 | | <?php echo $help_sidebar; ?> |
| 899 | <?php echo esc_html( $help_sidebar ); ?> |
900 | 900 | </div> |
901 | 901 | <?php endif; ?> |
902 | 902 | |
… |
… |
final class WP_Screen { |
907 | 907 | $panel_id = "tab-panel-{$tab['id']}"; |
908 | 908 | ?> |
909 | 909 | |
910 | | <div id="<?php echo esc_attr( $panel_id ); ?>" class="<?php echo $classes; ?>"> |
| 910 | <div id="<?php echo esc_attr( $panel_id ); ?>" class="<?php echo esc_attr( $classes ); ?>"> |
911 | 911 | <?php |
912 | 912 | // Print tab content. |
913 | | echo $tab['content']; |
| 913 | echo esc_html( $tab['content'] ); |
914 | 914 | |
915 | 915 | // If it exists, fire tab callback. |
916 | 916 | if ( ! empty( $tab['callback'] ) ) { |
… |
… |
final class WP_Screen { |
1160 | 1160 | $legend = ! empty( $columns['_title'] ) ? $columns['_title'] : __( 'Columns' ); |
1161 | 1161 | ?> |
1162 | 1162 | <fieldset class="metabox-prefs"> |
1163 | | <legend><?php echo $legend; ?></legend> |
| 1163 | <legend><?php echo esc_html( $legend ); ?></legend> |
1164 | 1164 | <?php |
1165 | 1165 | $special = array( '_title', 'cb', 'comment', 'media', 'name', 'title', 'username', 'blogname' ); |
1166 | 1166 | |
… |
… |
final class WP_Screen { |
1183 | 1183 | |
1184 | 1184 | $id = "$column-hide"; |
1185 | 1185 | echo '<label>'; |
1186 | | echo '<input class="hide-column-tog" name="' . $id . '" type="checkbox" id="' . $id . '" value="' . $column . '"' . checked( ! in_array( $column, $hidden, true ), true, false ) . ' />'; |
| 1186 | echo '<input class="hide-column-tog" name="' . esc_attr( $id ) . '" type="checkbox" id="' . esc_attr( $id ) . '" value="' . esc_attr( $column ) . '"' . checked( ! in_array( $column, $hidden, true ), true, false ) . ' />'; |
1187 | 1187 | echo "$title</label>\n"; |
1188 | 1188 | } |
1189 | 1189 | ?> |