Make WordPress Core


Ignore:
Timestamp:
09/14/2015 10:49:09 PM (11 years ago)
Author:
nbachiyski
Message:

Shortcodes: don't allow unclosed HTML elements in attributes

Merges [34134] for 3.7 branch

File:
1 edited

Legend:

Unmodified
Added
Removed
  • branches/3.7/src/wp-includes/media.php

    r25868 r34150  
    635635            $attr['caption'] = trim( $matches[2] );
    636636        }
     637    } elseif ( strpos( $attr['caption'], '<' ) !== false ) {
     638        $attr['caption'] = wp_kses( $attr['caption'], 'post' );
    637639    }
    638640
Note: See TracChangeset for help on using the changeset viewer.