Make WordPress Core


Ignore:
Timestamp:
08/27/2025 10:32:57 AM (4 months ago)
Author:
jonsurrell
Message:

Scripts: Use appropriate JSON encoding flags for script tags.

wp_json_encode() with default arguments is insufficient to safely escape JSON for script tags. Use JSON_HEX_TAG | JSON_UNESCAPED_SLASHES flags.

Developed in https://github.com/WordPress/wordpress-develop/pull/9557.

Props devasheeshkaul, jonsurrell, siliconforks.
Fixes #63851.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/wp-admin/includes/class-wp-privacy-policy-content.php

    r59733 r60681  
    349349                    'wp.data.dispatch( "core/notices" ).createWarningNotice( "%s", { actions: [ %s ], isDismissible: false } )',
    350350                    $message,
    351                     wp_json_encode( $action )
     351                    wp_json_encode( $action, JSON_HEX_TAG | JSON_UNESCAPED_SLASHES )
    352352                ),
    353353                'after'
Note: See TracChangeset for help on using the changeset viewer.