Make WordPress Core


Ignore:
Timestamp:
06/24/2024 03:08:05 PM (2 years ago)
Author:
audrasjb
Message:

Grouped Backports to the 6.4 branch.

  • Editor: Fix Path Traversal issue on Windows in Template-Part Block.
  • Editor: Sanitize Template Part HTML tag on save.
  • HTML API: Run URL attributes through esc_url().

Merges [58470], [58471], [58472] and [58473] to the 6.4 branch.
Props xknown, peterwilsoncc, jorbin, bernhard-reiter, azaozz, dmsnell, gziolo.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • branches/6.4/src/wp-includes/functions.php

    r57113 r58475  
    61466146    }
    61476147
     6148    // Normalize path for Windows servers
     6149    $file = wp_normalize_path( $file );
     6150
    61486151    // `../` on its own is not allowed:
    61496152    if ( '../' === $file ) {
Note: See TracChangeset for help on using the changeset viewer.