Changeset 37141
- Timestamp:
- 03/30/2016 05:40:10 PM (9 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/3.8/src/wp-includes/taxonomy.php
r26544 r37141 590 590 $term_ids = array_map('intval', $term_ids ); 591 591 592 $taxonomies = "'" . implode( "', '", $taxonomies) . "'";592 $taxonomies = "'" . implode( "', '", array_map( 'esc_sql', $taxonomies ) ) . "'"; 593 593 $term_ids = "'" . implode( "', '", $term_ids ) . "'"; 594 594 … … 1349 1349 $order = 'ASC'; 1350 1350 1351 $where = "tt.taxonomy IN ('" . implode("', '", $taxonomies) . "')";1351 $where = "tt.taxonomy IN ('" . implode("', '", array_map( 'esc_sql', $taxonomies ) ) . "')"; 1352 1352 $inclusions = ''; 1353 1353 if ( ! empty( $include ) ) { … … 2028 2028 $order = 'ASC'; 2029 2029 2030 $taxonomies = "'" . implode("', '", $taxonomies) . "'";2030 $taxonomies = "'" . implode("', '", array_map( 'esc_sql', $taxonomies ) ) . "'"; 2031 2031 $object_ids = implode(', ', $object_ids); 2032 2032
Note: See TracChangeset
for help on using the changeset viewer.