Make WordPress Core


Ignore:
Timestamp:
05/16/2023 03:18:41 PM (3 years ago)
Author:
audrasjb
Message:

Grouped backports to the 6.0 branch.

  • Media: Prevent CSRF setting attachment thumbnails.
  • Embeds: Add protocol validation for WordPress Embed code.
  • I18N: Introduce sanitization function for locale.
  • Editor: Ensure block comments are of a valid form.
  • Editor: Remove shortcode support from block templates.

Merges [55760-55764] to the 6.0 branch.
Props dd32, isabel_brison, martinkrcho, matveb, ocean90, paulkevan, peterwilsoncc, timothyblynjacobs, xknown, youknowriad.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • branches/6.0/src/wp-includes/media.php

    r53149 r55773  
    44124412        'captions'          => ! apply_filters( 'disable_captions', '' ),
    44134413        'nonce'             => array(
    4414             'sendToEditor' => wp_create_nonce( 'media-send-to-editor' ),
     4414            'sendToEditor'           => wp_create_nonce( 'media-send-to-editor' ),
     4415            'setAttachmentThumbnail' => wp_create_nonce( 'set-attachment-thumbnail' ),
    44154416        ),
    44164417        'post'              => array(
Note: See TracChangeset for help on using the changeset viewer.