Make WordPress Core

Changeset 29397 for trunk


Ignore:
Timestamp:
08/06/2014 07:49:30 AM (11 years ago)
Author:
nacin
Message:

Escape late in get_avatar().

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/wp-includes/pluggable.php

    r29382 r29397  
    21742174        $avatar = "<img alt='{$safe_alt}' src='{$out}' class='avatar avatar-{$size} photo' height='{$size}' width='{$size}' />";
    21752175    } else {
    2176         $avatar = "<img alt='{$safe_alt}' src='{$default}' class='avatar avatar-{$size} photo avatar-default' height='{$size}' width='{$size}' />";
     2176        $out = esc_url( $default );
     2177        $avatar = "<img alt='{$safe_alt}' src='{$out}' class='avatar avatar-{$size} photo avatar-default' height='{$size}' width='{$size}' />";
    21772178    }
    21782179
Note: See TracChangeset for help on using the changeset viewer.