Make WordPress Core

Changeset 34141


Ignore:
Timestamp:
09/14/2015 10:43:32 PM (10 years ago)
Author:
nbachiyski
Message:

List tables: escape user e-mails

Merges [34133] for 3.9 branch

Location:
branches/3.9/src/wp-admin/includes
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • branches/3.9/src/wp-admin/includes/class-wp-ms-users-list-table.php

    r27077 r34141  
    220220
    221221                    case 'email':
    222                         echo "<td $attributes><a href='mailto:$user->user_email'>$user->user_email</a></td>";
     222                        echo "<td $attributes><a href='" . esc_url( "mailto:$user->user_email" ) . "'>$user->user_email</a></td>";
    223223                    break;
    224224
  • branches/3.9/src/wp-admin/includes/class-wp-users-list-table.php

    r27355 r34141  
    418418                    break;
    419419                case 'email':
    420                     $r .= "<td $attributes><a href='mailto:$email' title='" . esc_attr( sprintf( __( 'E-mail: %s' ), $email ) ) . "'>$email</a></td>";
     420                    $r .= "<td $attributes><a href='" . esc_url( "mailto:$email" ) . "' title='" . esc_attr( sprintf( __( 'E-mail: %s' ), $email ) ) . "'>$email</a></td>";
    421421                    break;
    422422                case 'role':
Note: See TracChangeset for help on using the changeset viewer.