Changeset 37142
- Timestamp:
- 03/30/2016 05:42:44 PM (7 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/3.7/src/wp-includes/taxonomy.php
r25936 r37142 588 588 $term_ids = array_map('intval', $term_ids ); 589 589 590 $taxonomies = "'" . implode( "', '", $taxonomies) . "'";590 $taxonomies = "'" . implode( "', '", array_map( 'esc_sql', $taxonomies ) ) . "'"; 591 591 $term_ids = "'" . implode( "', '", $term_ids ) . "'"; 592 592 … … 1347 1347 $order = 'ASC'; 1348 1348 1349 $where = "tt.taxonomy IN ('" . implode("', '", $taxonomies) . "')";1349 $where = "tt.taxonomy IN ('" . implode("', '", array_map( 'esc_sql', $taxonomies ) ) . "')"; 1350 1350 $inclusions = ''; 1351 1351 if ( ! empty( $include ) ) { … … 2030 2030 $order = 'ASC'; 2031 2031 2032 $taxonomies = "'" . implode("', '", $taxonomies) . "'";2032 $taxonomies = "'" . implode("', '", array_map( 'esc_sql', $taxonomies ) ) . "'"; 2033 2033 $object_ids = implode(', ', $object_ids); 2034 2034
Note: See TracChangeset
for help on using the changeset viewer.