Make WordPress Core

Changeset 17146


Ignore:
Timestamp:
12/25/2010 10:45:09 PM (12 years ago)
Author:
ryan
Message:

link_notes and term_description escaping fixes. Props garyc40. fixes #15454

Location:
trunk/wp-includes
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-includes/bookmark.php

    r15590 r17146  
    335335
    336336    if ( 'edit' == $context ) {
    337         $format_to_edit = array('link_notes');
    338337        $value = apply_filters("edit_$field", $value, $bookmark_id);
    339338
    340         if ( in_array($field, $format_to_edit) ) {
    341             $value = format_to_edit($value);
     339        if ( 'link_notes' == $field ) {
     340            $value = esc_html( $value ); // textarea_escaped
    342341        } else {
    343342            $value = esc_attr($value);
  • trunk/wp-includes/taxonomy.php

    r17028 r17146  
    15221522        $value = apply_filters("edit_{$taxonomy}_{$field}", $value, $term_id);
    15231523        if ( 'description' == $field )
    1524             $value = format_to_edit($value);
     1524            $value = esc_html($value); // textarea_escaped
    15251525        else
    15261526            $value = esc_attr($value);
Note: See TracChangeset for help on using the changeset viewer.