|
#40485
|
Add function for retrieving metadata from registered script
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
feature request
|
12 months ago
|
|
#59972
|
Clarify description of wp_script_add_data()
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
22 months ago
|
|
#65750
|
Compression test sends unauthorized AJAX requests for users without manage_options
|
|
has-patch
|
normal
|
minor
|
Future Release
|
defect (bug)
|
13 days ago
|
|
#13078
|
Make wp_register_style and wp_enqueue_style consistent
|
|
has-patch
|
normal
|
normal
|
|
defect (bug)
|
7 years ago
|
|
#58075
|
wp_enqueue_scripts action not firing at the right time with block themes
|
|
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
3 years ago
|
|
#47350
|
Add method to get JSON from a file without using file_get_contents()
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
7 years ago
|
|
#38800
|
add WP_ADMIN_URL and WP_INCLUDES_URL constants
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
9 years ago
|
|
#47789
|
NGINX: Request for media-view.js leads to "zero size buf in writer"
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
7 years ago
|
|
#64812
|
Scripts: wp_enqueue_registered_block_scripts_and_styles() does not include modules
|
|
has-patch
|
normal
|
normal
|
Future Release
|
defect (bug)
|
4 months ago
|
|
#59132
|
Create two filters in wp_scripts() and wp_styles().
|
|
reporter-feedback
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
3 years ago
|
|
#25666
|
Pass perpetrating $handle to enqueue_script's _doing_it_wrong() call
|
|
|
normal
|
normal
|
|
enhancement
|
7 years ago
|
|
#60234
|
Script Modules API: Add a translations API
|
|
|
normal
|
normal
|
7.2
|
enhancement
|
5 weeks ago
|
|
#36791
|
Set load order when enqueuing scripts and styles
|
|
has-patch
|
normal
|
normal
|
|
enhancement
|
7 years ago
|
|
#53638
|
Duplicate inline JS
|
|
|
normal
|
minor
|
|
defect (bug)
|
2 years ago
|
|
#49470
|
Script loader: simplify maintenance
|
|
|
normal
|
normal
|
Future Release
|
defect (bug)
|
6 years ago
|
|
#39991
|
jQuery UI Datepicker Localization Error with PHP date 'S'
|
|
has-patch
|
normal
|
normal
|
Future Release
|
defect (bug)
|
8 years ago
|
|
#52465
|
Allow a relation type in resource hints to be used multiple times
|
|
has-patch
|
normal
|
normal
|
Future Release
|
enhancement
|
5 years ago
|
|
#40602
|
Implement immutable cache headers
|
pbearne
|
has-patch
|
normal
|
normal
|
Future Release
|
enhancement
|
18 months ago
|
|
#20558
|
allow wp_localize_script data to be added to existing objects
|
|
dev-feedback
|
normal
|
normal
|
|
enhancement
|
7 years ago
|
|
#40276
|
enhancement: add a $type parameter to wp_add_inline_script()
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
3 months ago
|
|
#56425
|
wp_localize_script assign to const and freeze instead of var to avoid reassignments
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
4 years ago
|
|
#47285
|
Better Management of External Asset Dependencies
|
|
|
normal
|
major
|
Awaiting Review
|
feature request
|
2 years ago
|
|
#43900
|
Add hint about blocked Javascript as possible error reason in script-loader.php
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
8 years ago
|
|
#49742
|
No longer able to enqueue multiple Google Fonts with wp_enqueue_style
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
5 years ago
|
|
#54956
|
[5.9] wp_block_type args - "style" and "script" are always loaded on Frontend
|
|
needs-unit-tests
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
4 years ago
|
|
#62709
|
Script modules integration with wp_resource_hints
|
|
has-patch
|
normal
|
minor
|
7.2
|
enhancement
|
4 weeks ago
|
|
#51325
|
Add a filter for script/style tags injected by wp_add_inline_{script|style}
|
|
dev-feedback
|
normal
|
normal
|
Future Release
|
enhancement
|
11 days ago
|
|
#61625
|
Styles enqueued from block.json are not correctly configured for RTL
|
westonruter*
|
has-patch
|
normal
|
normal
|
Future Release
|
defect (bug)
|
8 days ago
|
|
#61828
|
Global Styles: Refactor wp_add_inline_style() to use HTML API
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
2 years ago
|
|
#21520
|
Prevent recursive script dependencies in wp_enqueue_script
|
|
|
normal
|
normal
|
|
defect (bug)
|
7 years ago
|
|
#52879
|
The SCRIPT_DEBUG constant is ignored when concatenating scripts
|
|
|
normal
|
minor
|
Future Release
|
defect (bug)
|
4 years ago
|
|
#51317
|
Remove deprecated JavaScript i18n globals
|
|
has-patch
|
normal
|
normal
|
Future Release
|
enhancement
|
4 months ago
|
|
#51837
|
Adding `add_theme_support` for html5 for scripts, does not remove the type attribute from `wp-emoji-release.min.js`
|
SergeyBiryukov
|
has-patch
|
normal
|
normal
|
Future Release
|
defect (bug)
|
21 months ago
|
|
#63017
|
Compression via PHP documented and in URL but not used anymore
|
|
has-patch
|
normal
|
normal
|
Future Release
|
defect (bug)
|
3 months ago
|
|
#63805
|
Extend the existing conditional loading optimization for block-specific global styles from core blocks to include third-party blocks, improving performance by only loading styles for blocks actually present on the page.
|
|
has-patch
|
normal
|
normal
|
Future Release
|
enhancement
|
10 months ago
|
|
#46089
|
Memory exhaustion when setting script translations on `wp-i18n`
|
|
needs-unit-tests
|
normal
|
normal
|
Future Release
|
defect (bug)
|
6 years ago
|
|
#58302
|
Deprecate and disable the unused compression_test() and wp_ajax_wp_compression_test()
|
|
has-patch
|
normal
|
normal
|
Future Release
|
enhancement
|
10 months ago
|
|
#58873
|
Add function to pass variables to scripts
|
|
has-patch
|
normal
|
normal
|
Future Release
|
feature request
|
6 weeks ago
|
|
#63793
|
Parser-blocking scripts should render last in all cases to speed up page load
|
|
has-patch
|
normal
|
normal
|
Future Release
|
enhancement
|
12 months ago
|
|
#65272
|
Blocks' opinionated styles are not loading on demand in classic themes
|
westonruter*
|
has-patch
|
normal
|
normal
|
7.2
|
defect (bug)
|
7 days ago
|
|
#55184
|
Custom style handle attached to a custom block style is never load even if the block is in the page.
|
|
needs-unit-tests
|
normal
|
normal
|
Future Release
|
defect (bug)
|
5 months ago
|
|
#60597
|
Script Modules API: Allow list of enqueued module data to be exposed
|
westonruter
|
has-patch
|
normal
|
normal
|
7.2
|
enhancement
|
4 weeks ago
|
|
#57548
|
Stop concatenating scripts and stylesheets in wp-admin and retire load-scripts.php and load-styles.php
|
westonruter*
|
has-patch
|
normal
|
normal
|
7.2
|
enhancement
|
4 weeks ago
|
|
#54018
|
Allow scripts registered via block.json to be enqueued in the footer
|
|
has-patch
|
normal
|
normal
|
Future Release
|
enhancement
|
10 months ago
|
|
#65515
|
ThickBox ReferenceError: imgLoader is not defined due to "use strict" contamination in load-scripts.php
|
wildworks
|
reporter-feedback
|
normal
|
normal
|
Future Release
|
defect (bug)
|
18 hours ago
|
|
#17916
|
Enqueued styles are only printed on login_footer in wp-login.php
|
|
dev-feedback
|
normal
|
normal
|
Future Release
|
defect (bug)
|
8 years ago
|
|
#52333
|
Lack of the : entity on the list of allowed entity names in kses.php
|
|
has-patch
|
normal
|
minor
|
Awaiting Review
|
defect (bug)
|
6 years ago
|
|
#63940
|
Prevent POST flood cache bypass attacks
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
11 months ago
|
|
#53994
|
REST API requests with session cookies but an invalid/missing nonce are considered authenticated for most of the request
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
5 years ago
|
|
#56860
|
Sodium Compat library is improperly loaded
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
21 months ago
|
|
#57447
|
wp_ajax_inline_save function does not check if post has "public" or "show_ui" enabled
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
4 years ago
|
|
#58636
|
Automatic Sanitization of Nonces in wp_verify_nonce
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
3 years ago
|
|
#62949
|
HttpOnly flag for the post password cookie
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
18 months ago
|
|
#57424
|
Specific hook for Content Security Policy
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
4 years ago
|
|
#41391
|
Links to media in password protected pages
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
9 years ago
|
|
#65574
|
Unsafe usage of href attribute in wp-admin/js/common.js
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
4 weeks ago
|
|
#65572
|
Unsafe usage of href attribute in wp-admin/js/post.js
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
3 weeks ago
|
|
#58679
|
meta key field in usermeta table should NOT use accent insensitive collations
|
|
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
12 months ago
|
|
#56521
|
wp_kses wp_kses_hair fails to allow a valueless attribute when is follwed by /
|
|
has-patch
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
4 years ago
|
|
#62384
|
.htaccess lacks
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
20 months ago
|
|
#51611
|
Escape echoing Core functions
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
6 years ago
|
|
#64481
|
Explore Sec-Fetch Headers as a Core-Supported CSRF Mitigation Mechanism
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
7 months ago
|
|
#61706
|
Support for storing and getting encrypted options
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
18 months ago
|
|
#63329
|
Use check_ajax_referer() instead of check_admin_referer() for AJAX requests in media form handling.
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
16 months ago
|
|
#65573
|
Unsafe usage of href attribute in wp-admin/js/link.js
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
13 hours ago
|
|
#63457
|
WordPress 6.8 will fail creating bcrypt when entropy sources are not available
|
|
reporter-feedback
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
15 months ago
|
|
#62693
|
check if chmod is available to prevent Fatal Errors
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
20 months ago
|
|
#43320
|
Harden API requests against man-in-the-middle attacks
|
|
|
low
|
minor
|
Awaiting Review
|
enhancement
|
8 years ago
|
|
#53869
|
Post type / Taxonomy Label Hardening: Prevent Raw HTML tags in output / Media Library eval of HTML entities in label
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
5 years ago
|
|
#44058
|
Include security sniffs in PHPCS ruleset
|
|
|
normal
|
normal
|
Future Release
|
enhancement
|
8 years ago
|
|
#36087
|
Migration plan from insecure RNG fallback
|
|
|
normal
|
normal
|
Future Release
|
enhancement
|
6 years ago
|
|
#60470
|
Use `filter_input` instead of superglobals where possible
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
3 years ago
|
|
#55514
|
2FA by default for WordPress
|
|
|
normal
|
normal
|
Awaiting Review
|
feature request
|
3 years ago
|
|
#63259
|
Replace zxcvbn with zxcvbn-ts
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
16 months ago
|
|
#51438
|
Use CSP directive upgrade-insecure-requests when using HTTPS
|
|
needs-unit-tests
|
normal
|
normal
|
Future Release
|
enhancement
|
5 years ago
|
|
#43215
|
Allow wp_kses to pass allowed CSS properties
|
|
|
normal
|
normal
|
Awaiting Review
|
feature request
|
9 months ago
|
|
#53902
|
Automating the creation of inline javascript and inline stylesheet nonces or hashes
|
|
|
normal
|
normal
|
Awaiting Review
|
feature request
|
2 years ago
|
|
#62134
|
Security Issue in WordPress Core
|
|
|
normal
|
normal
|
|
defect (bug)
|
22 months ago
|
|
#60864
|
URL sanitizing strips valid characters instead of encoding, documented use is invalid
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
7 months ago
|
|
#62202
|
allow plugin versions to be flagged as security updates
|
|
close
|
normal
|
normal
|
Awaiting Review
|
feature request
|
22 months ago
|
|
#31686
|
wp_authenticate_username_password() should check for a WP_Error object
|
|
reporter-feedback
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
7 years ago
|
|
#65052
|
Nonce check order flaw in post-quickdraft-save
|
rajeshcp
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
3 months ago
|
|
#51159
|
Let's expand our context specific escaping methods for wp_json_encode().
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
7 months ago
|
|
#37264
|
Please do not chmod 666 the wp-config.php file on installation.
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
7 years ago
|
|
#40237
|
Educate users about modern password best-practices
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
4 years ago
|
|
#63727
|
A new function to sanitize an array
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
13 months ago
|
|
#53973
|
WordPress <= 5.8 - Authenticated Persistent XSS (User role name)
|
|
has-patch
|
normal
|
normal
|
Future Release
|
defect (bug)
|
17 months ago
|
|
#56391
|
safecss_filter_attr(): support rgba background-color
|
|
has-patch
|
normal
|
normal
|
|
defect (bug)
|
6 months ago
|
|
#37757
|
Add `allowed_classes` to `maybe_unserialize` When WordPress is running on PHP 7+
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
16 months ago
|
|
#65054
|
$_GET['pagenow'] and $_GET['widget'] unsanitized in dashboard AJAX handler
|
rajeshcp
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
3 weeks ago
|
|
#65448
|
Use the new Uri\Rfc3986\Uri::parse in wp_parse_url() if PHP 8.5 is available
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
7 weeks ago
|
|
#51407
|
Remove inline event handlers and JavaScript URIs for Strict CSP-compatibility
|
adamsilverstein
|
dev-feedback
|
normal
|
normal
|
Future Release
|
enhancement
|
4 weeks ago
|
|
#23165
|
Admin validation errors on form nonce element IDs (_wpnonce)
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
6 years ago
|
|
#56141
|
Enhance installer security
|
|
dev-feedback
|
high
|
major
|
Future Release
|
enhancement
|
6 weeks ago
|
|
#64789
|
Security audit for API key storage on the Connectors screen
|
|
dev-feedback
|
normal
|
normal
|
Future Release
|
task (blessed)
|
4 days ago
|
|
#32067
|
Remove inline javascript from WP-Core to allow CSP protection
|
|
close
|
normal
|
normal
|
Future Release
|
feature request
|
3 months ago
|
|
#36177
|
default htaccess should include security measures
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
20 months ago
|
|
#20140
|
Ask old password to change user password
|
|
dev-feedback
|
normal
|
major
|
Future Release
|
feature request
|
3 weeks ago
|
|
#28521
|
FORCE_SSL constant for really forcing SSL
|
adamsilverstein
|
has-patch
|
normal
|
normal
|
Future Release
|
enhancement
|
6 weeks ago
|
|
#38474
|
wp_signups.activation_key stores activation keys in plain text
|
SergeyBiryukov
|
dev-feedback
|
normal
|
normal
|
Future Release
|
enhancement
|
6 weeks ago
|