WordPress.org

Make WordPress Core


Ignore:
Timestamp:
03/28/10 01:32:35 (4 years ago)
Author:
dd32
Message:

Properly escape plugin admin menu URL's for display. Crops up with custom post_type's with a custom submenu item with & instead of &

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/menu-header.php

    r13770 r13851  
    145145                    else 
    146146                        $sub_item_url = add_query_arg( array('page' => $sub_item[2]), 'admin.php' ); 
     147                    $sub_item_url = esc_url($sub_item_url); 
    147148                    echo "<li$class><a href='$sub_item_url'$class$tabindex>{$sub_item[0]}</a></li>"; 
    148149                } else { 
Note: See TracChangeset for help on using the changeset viewer.