Make WordPress Core


Ignore:
Timestamp:
09/14/2015 10:32:52 PM (11 years ago)
Author:
nbachiyski
Message:

List tables: escape user e-mails

Better safe than sorry.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/wp-admin/includes/class-wp-users-list-table.php

    r33774 r34133  
    435435                        break;
    436436                    case 'email':
    437                         $r .= "<a href='mailto:$email'>$email</a>";
     437                        $r .= "<a href='" . esc_url( "mailto:$email" ) . "'>$email</a>";
    438438                        break;
    439439                    case 'role':
Note: See TracChangeset for help on using the changeset viewer.