WordPress.org

Make WordPress Core

Ticket #8878: 8878.4.patch

File 8878.4.patch, 910 bytes (added by Viper007Bond, 7 years ago)

Ensure get_the_title() is escaped

  • wp-includes/general-template.php

     
    14361436        if ( is_single() || is_page() ) { 
    14371437                $post = &get_post( $id = 0 ); 
    14381438                if ( comments_open() || pings_open() || $post->comment_count > 0 ) 
    1439                         echo '<link rel="alternate" type="' . feed_content_type() . '" title="' . sprintf( $args['singletitle'], get_bloginfo('name'), $args['seperator'], get_the_title() ) . '" href="' . get_post_comments_feed_link( $post->ID ) . "\" />\n"; 
     1439                        echo '<link rel="alternate" type="' . feed_content_type() . '" title="' . sprintf( $args['singletitle'], get_bloginfo('name'), $args['seperator'], wp_specialchars( get_the_title() ) ) . '" href="' . get_post_comments_feed_link( $post->ID ) . "\" />\n"; 
    14401440        } 
    14411441 
    14421442        elseif ( is_category() ) {