WordPress.org

Make WordPress Core

Ticket #7423: 7423.001.diff

File 7423.001.diff, 541 bytes (added by markjaquith, 6 years ago)
  • wp-includes/query.php

     
    773773                        $qv['post_type'] = sanitize_user($qv['post_type'], true); 
    774774 
    775775                if ( !empty($qv['post_status']) ) 
    776                         $qv['post_status'] = sanitize_user($qv['post_status'], true); 
     776                        $qv['post_status'] = preg_replace('|[^a-z0-9_,-]|', '', $qv['post_status']); 
    777777 
    778778                if ( $this->is_posts_page && !$qv['withcomments'] ) 
    779779                        $this->is_comment_feed = false;