WordPress.org

Make WordPress Core

Changeset 37780


Ignore:
Timestamp:
06/21/2016 02:19:42 PM (4 years ago)
Author:
ocean90
Message:

Customize: Make sure that preview and return URLs are URLs.

Merge of [37527] to the 3.7 branch.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • branches/3.7/src/wp-admin/customize.php

    r25858 r37780  
    1616wp_reset_vars( array( 'url', 'return' ) );
    1717$url = urldecode( $url );
     18$url = esc_url_raw( $url );
    1819$url = wp_validate_redirect( $url, home_url( '/' ) );
    1920if ( $return )
    20     $return = wp_validate_redirect( urldecode( $return ) );
     21    $return = wp_validate_redirect( esc_url_raw( urldecode( $return ) ) );
    2122if ( ! $return )
    2223    $return = $url;
Note: See TracChangeset for help on using the changeset viewer.