Make WordPress Core

Changeset 34143


Ignore:
Timestamp:
09/14/2015 10:44:46 PM (9 years ago)
Author:
nbachiyski
Message:

List tables: escape user e-mails

Merges [34133] for 3.7 branch

Location:
branches/3.7/src/wp-admin/includes
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • branches/3.7/src/wp-admin/includes/class-wp-ms-users-list-table.php

    r23563 r34143  
    202202
    203203                    case 'email':
    204                         echo "<td $attributes><a href='mailto:$user->user_email'>$user->user_email</a></td>";
     204                        echo "<td $attributes><a href='" . esc_url( "mailto:$user->user_email" ) . "'>$user->user_email</a></td>";
    205205                    break;
    206206
  • branches/3.7/src/wp-admin/includes/class-wp-users-list-table.php

    r24123 r34143  
    295295                    break;
    296296                case 'email':
    297                     $r .= "<td $attributes><a href='mailto:$email' title='" . esc_attr( sprintf( __( 'E-mail: %s' ), $email ) ) . "'>$email</a></td>";
     297                    $r .= "<td $attributes><a href='" . esc_url( "mailto:$email" ) . "' title='" . esc_attr( sprintf( __( 'E-mail: %s' ), $email ) ) . "'>$email</a></td>";
    298298                    break;
    299299                case 'role':
Note: See TracChangeset for help on using the changeset viewer.