Make WordPress Core


Ignore:
Timestamp:
06/21/2021 04:29:18 AM (3 years ago)
Author:
SergeyBiryukov
Message:

Administration: Consistently escape network_admin_url() links.

Follow-up to [51177].

Props chintan1896, mukesh27.
Fixes #53459.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/wp-admin/network/site-users.php

    r49944 r51189  
    331331    ?>
    332332<h2 id="add-new-user"><?php _e( 'Add New User' ); ?></h2>
    333 <form action="<?php echo network_admin_url( 'site-users.php?action=newuser' ); ?>" id="newuser" method="post">
     333<form action="<?php echo esc_url( network_admin_url( 'site-users.php?action=newuser' ) ); ?>" id="newuser" method="post">
    334334    <input type="hidden" name="id" value="<?php echo esc_attr( $id ); ?>" />
    335335    <table class="form-table" role="presentation">
Note: See TracChangeset for help on using the changeset viewer.