WordPress.org

Make WordPress Core

Ticket #7423: 7423.001.diff

File 7423.001.diff, 541 bytes (added by markjaquith, 10 years ago)
  • wp-includes/query.php

     
    773773                        $qv['post_type'] = sanitize_user($qv['post_type'], true);
    774774
    775775                if ( !empty($qv['post_status']) )
    776                         $qv['post_status'] = sanitize_user($qv['post_status'], true);
     776                        $qv['post_status'] = preg_replace('|[^a-z0-9_,-]|', '', $qv['post_status']);
    777777
    778778                if ( $this->is_posts_page && !$qv['withcomments'] )
    779779                        $this->is_comment_feed = false;