Make WordPress Core


Ignore:
Timestamp:
09/28/2022 12:38:49 PM (21 months ago)
Author:
audrasjb
Message:

Twenty Ten: Escape get_author_posts_url() where appropriate in functions.php file.

This changeset adds missing escaping to some instances of get_author_posts_url() used in Twenty Ten, as per WordPress Coding Standards.

Props hztyfoon, robinwpdeveloper, mukesh27, rudlinkon, SergeyBiryukov, jakariaistauk.
Fixes #56674.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/wp-content/themes/twentyten/loop-attachment.php

    r51553 r54344  
    4646                                sprintf(
    4747                                    '<span class="author vcard"><a class="url fn n" href="%1$s" title="%2$s" rel="author">%3$s</a></span>',
    48                                     get_author_posts_url( get_the_author_meta( 'ID' ) ),
     48                                    esc_url( get_author_posts_url( get_the_author_meta( 'ID' ) ) ),
    4949                                    /* translators: %s: Author display name. */
    5050                                    esc_attr( sprintf( __( 'View all posts by %s', 'twentyten' ), get_the_author() ) ),
Note: See TracChangeset for help on using the changeset viewer.