WordPress.org

Make WordPress Core

Ticket #8878: 8878.4.patch

File 8878.4.patch, 910 bytes (added by Viper007Bond, 9 years ago)

Ensure get_the_title() is escaped

  • wp-includes/general-template.php

     
    14361436        if ( is_single() || is_page() ) {
    14371437                $post = &get_post( $id = 0 );
    14381438                if ( comments_open() || pings_open() || $post->comment_count > 0 )
    1439                         echo '<link rel="alternate" type="' . feed_content_type() . '" title="' . sprintf( $args['singletitle'], get_bloginfo('name'), $args['seperator'], get_the_title() ) . '" href="' . get_post_comments_feed_link( $post->ID ) . "\" />\n";
     1439                        echo '<link rel="alternate" type="' . feed_content_type() . '" title="' . sprintf( $args['singletitle'], get_bloginfo('name'), $args['seperator'], wp_specialchars( get_the_title() ) ) . '" href="' . get_post_comments_feed_link( $post->ID ) . "\" />\n";
    14401440        }
    14411441
    14421442        elseif ( is_category() ) {