#40276
|
enhancement: add a $type parameter to wp_add_inline_script()
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
11/08/2021
|
#51124
|
Can we get an additional parameter in wp_add_inline_script to set the script type?
|
audrasjb*
|
needs-unit-tests
|
normal
|
normal
|
Future Release
|
feature request
|
11/08/2021
|
#53741
|
wp-admin/css/common.min.css is loading on the front-end
|
|
needs-docs
|
normal
|
normal
|
Future Release
|
defect (bug)
|
11/02/2021
|
#51317
|
Remove deprecated JavaScript i18n globals
|
|
early
|
normal
|
normal
|
Future Release
|
enhancement
|
05/25/2021
|
#52320
|
Empty entries in WP_Scripts 'extra' field
|
|
|
normal
|
trivial
|
Awaiting Review
|
defect (bug)
|
02/23/2021
|
#52497
|
New filter "wp_script_attributes" doesn't take effort in enqueued scripts
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
02/11/2021
|
#46089
|
Memory exhaustion when setting script translations on `wp-i18n`
|
|
needs-unit-tests
|
normal
|
normal
|
Future Release
|
defect (bug)
|
02/04/2021
|
#44211
|
Add cookie domain to `userSettings` script localize
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
feature request
|
10/12/2020
|
#51200
|
Consider a better way to deprecate JavaScript code
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
08/31/2020
|
#49470
|
Script loader: simplify maintenance
|
|
|
normal
|
normal
|
Future Release
|
defect (bug)
|
07/21/2020
|
#49192
|
All plugin style tags are empty after upgrade to 5.3.2
|
|
reporter-feedback
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
01/20/2020
|
#37756
|
Allow inline scripts on script aliases
|
|
needs-unit-tests
|
normal
|
normal
|
Future Release
|
defect (bug)
|
12/13/2019
|
#48880
|
Using JSON.parse instead of an actual object literal when localizing scripts
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
12/06/2019
|
#47789
|
NGINX: Request for media-view.js leads to "zero size buf in writer"
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
10/20/2019
|
#37388
|
Resource hinting: only dns-prefetch resources in HTML footer.
|
|
|
normal
|
normal
|
|
enhancement
|
06/04/2019
|
#37185
|
wp_print_styles() doesn't call "wp_print_styles" action when "$handles" argument passed
|
|
needs-unit-tests
|
normal
|
normal
|
|
defect (bug)
|
06/04/2019
|
#36791
|
Set load order when enqueuing scripts and styles
|
|
has-patch
|
normal
|
normal
|
|
enhancement
|
06/04/2019
|
#36779
|
Move /wp-admin/load-scripts.php and /wp-admin/load-styles.php to /wp-includes
|
|
|
normal
|
normal
|
|
defect (bug)
|
06/04/2019
|
#36449
|
When concatenating styles in script-loader dependencies may not be honoured.
|
|
|
normal
|
normal
|
|
defect (bug)
|
06/04/2019
|
#36448
|
When concatenating scripts in script-loader dependencies may not be honoured.
|
|
|
normal
|
normal
|
|
defect (bug)
|
06/04/2019
|
#35963
|
Only remove item from WP_Dependencies::to_do if it was successfully processed
|
|
needs-unit-tests
|
normal
|
normal
|
|
defect (bug)
|
06/04/2019
|
#35331
|
Update external Prototype library to 1.7.3
|
|
has-patch
|
normal
|
normal
|
|
enhancement
|
06/04/2019
|
#31281
|
Register JavaScript/Underscore templates using the WP Dependency API
|
|
has-patch
|
normal
|
normal
|
|
enhancement
|
06/04/2019
|
#30036
|
Add some escaping to $handle when printing styles.
|
|
|
normal
|
normal
|
|
defect (bug)
|
06/04/2019
|
#26113
|
Create a WordPress-specific, dependable reference to the WP-bundled jQuery object.
|
|
|
normal
|
normal
|
|
defect (bug)
|
06/04/2019
|
#25666
|
Pass perpetrating $handle to enqueue_script's _doing_it_wrong() call
|
|
|
normal
|
normal
|
|
enhancement
|
06/04/2019
|
#24713
|
Compression in load_styles.php does not always work, causing inability to use the admin
|
|
|
normal
|
normal
|
|
defect (bug)
|
06/04/2019
|
#21520
|
Prevent recursive script dependencies in wp_enqueue_script
|
|
|
normal
|
normal
|
|
defect (bug)
|
06/04/2019
|
#20558
|
allow wp_localize_script data to be added to existing objects
|
|
dev-feedback
|
normal
|
normal
|
|
enhancement
|
06/04/2019
|
#13078
|
Make wp_register_style and wp_enqueue_style consistent
|
|
has-patch
|
normal
|
normal
|
|
defect (bug)
|
06/04/2019
|
#47350
|
Add method to get JSON from a file without using file_get_contents()
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
05/22/2019
|
#15833
|
Script concatenation fails to take external dependencies into account.
|
|
|
normal
|
normal
|
Future Release
|
defect (bug)
|
05/21/2019
|
#47322
|
scenario based-bug in the file load-style.php
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
05/20/2019
|
#38054
|
class.wp-scripts.php - add_action when init is already doing
|
|
reporter-feedback
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
04/09/2019
|
#38548
|
Add new filters on wp_script_is/wp_style_is
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
03/26/2019
|
#46334
|
wp_localize_script did not output anything in wp_print_footer_scripts hook although document suggested that it should be working
|
|
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
02/24/2019
|
#45106
|
Concerns related to moving mce_external_plugins filter to WP_Scripts::__construct
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
01/16/2019
|
#43825
|
Style/script loading infrastructure: Etag header as a hash of script/style handles and their corresponding versions
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
01/16/2019
|
#37162
|
wp_style_add_data and wp_script_add_data should accept SRI information
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
11/14/2018
|
#39991
|
jQuery UI Datepicker Localization Error with PHP date 'S'
|
|
has-patch
|
normal
|
normal
|
Future Release
|
defect (bug)
|
10/25/2018
|
#45008
|
Inconsistent use of 'script_loader_src' and 'style_loader_src' filters when performing concatenation
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
09/27/2018
|
#17916
|
Enqueued styles are only printed on login_footer in wp-login.php
|
|
dev-feedback
|
normal
|
normal
|
Future Release
|
defect (bug)
|
08/10/2018
|
#43900
|
Add hint about blocked Javascript as possible error reason in script-loader.php
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
05/02/2018
|
#43781
|
adding apply_filters on $handle in localize
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
04/16/2018
|
#43403
|
Improve wp_add_inline_script()
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
02/24/2018
|
#37362
|
@font-face errors with dashicons in Microsoft Edge
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
12/11/2017
|
#42440
|
Uncaught TypeError: $(...).wpColorPicker is not a function
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
11/06/2017
|
#38800
|
add WP_ADMIN_URL and WP_INCLUDES_URL constants
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
09/29/2017
|
#40485
|
Add function for retrieving metadata from registered script
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
feature request
|
06/07/2017
|
#40737
|
Script tags inside unclosed HTML comment in value passed to WP_Script->localize() breaks page
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
06/01/2017
|
#40134
|
Invalid data for scripts in footer
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
03/12/2017
|
#34591
|
BugFix to WP_Scripts::do_item(), remove doubled "//"
|
|
needs-unit-tests
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
02/05/2017
|
#53973
|
WordPress <= 5.8 - Authenticated Persistent XSS (User role name)
|
|
has-patch
|
normal
|
normal
|
Future Release
|
defect (bug)
|
03/12/2025
|
#37757
|
Add `allowed_classes` to `maybe_unserialize` When WordPress is running on PHP 7+
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
02/21/2025
|
#43215
|
Allow wp_kses to pass allowed CSS properties
|
|
|
normal
|
normal
|
Awaiting Review
|
feature request
|
02/21/2025
|
#43936
|
Settings: Warn when open registration and new user default is privileged
|
audrasjb*
|
has-patch
|
normal
|
normal
|
6.9
|
feature request
|
02/20/2025
|
#61706
|
Support for storing and getting encrypted options
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
02/18/2025
|
#62949
|
HttpOnly flag for the post password cookie
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
02/12/2025
|
#59824
|
PHP Warning raised in pluggable.php when passing NULL instead of a string
|
|
reporter-feedback
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
02/01/2025
|
#30465
|
Dashboard alert if a plugin/theme was removed from WordPress repo
|
|
dev-feedback
|
normal
|
normal
|
Future Release
|
feature request
|
01/24/2025
|
#36177
|
default htaccess should include security measures
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
12/24/2024
|
#62693
|
check if chmod is available to prevent Fatal Errors
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
12/14/2024
|
#62384
|
.htaccess lacks
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
12/09/2024
|
#56860
|
Sodium Compat library is improperly loaded
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
11/19/2024
|
#28521
|
FORCE_SSL constant for really forcing SSL
|
adamsilverstein
|
|
normal
|
normal
|
Future Release
|
enhancement
|
11/19/2024
|
#62134
|
Security Issue in WordPress Core
|
|
|
normal
|
normal
|
|
defect (bug)
|
10/14/2024
|
#62202
|
allow plugin versions to be flagged as security updates
|
|
close
|
normal
|
normal
|
Awaiting Review
|
feature request
|
10/10/2024
|
#20140
|
Ask old password to change user password
|
|
dev-feedback
|
normal
|
major
|
Future Release
|
feature request
|
07/28/2024
|
#53902
|
Automating the creation of inline javascript and inline stylesheet nonces or hashes
|
|
|
normal
|
normal
|
Awaiting Review
|
feature request
|
07/03/2024
|
#32067
|
Remove inline javascript from WP-Core to allow CSP protection
|
|
|
normal
|
normal
|
Future Release
|
feature request
|
06/18/2024
|
#37000
|
Support for the SameSite cookie attribute
|
|
dev-feedback
|
normal
|
normal
|
Future Release
|
enhancement
|
06/06/2024
|
#51159
|
Let's expand our context specific escaping methods for wp_json_encode().
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
05/09/2024
|
#38474
|
wp_signups.activation_key stores activation keys in plain text
|
SergeyBiryukov
|
has-patch
|
normal
|
normal
|
Future Release
|
enhancement
|
04/23/2024
|
#60864
|
URL sanitizing strips valid characters instead of encoding, documented use is invalid
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
04/03/2024
|
#60470
|
Use `filter_input` instead of superglobals where possible
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
02/09/2024
|
#56141
|
Enhance installer security
|
|
dev-feedback
|
high
|
major
|
Future Release
|
enhancement
|
12/31/2023
|
#51407
|
Remove inline event handlers and JavaScript URIs for Strict CSP-compatibility
|
adamsilverstein
|
dev-feedback
|
normal
|
normal
|
Future Release
|
enhancement
|
12/26/2023
|
#58679
|
meta key field in usermeta table should NOT use accent insensitive collations
|
|
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
10/30/2023
|
#58636
|
Automatic Sanitization of Nonces in wp_verify_nonce
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
06/26/2023
|
#55514
|
2FA by default for WordPress
|
|
|
normal
|
normal
|
Awaiting Review
|
feature request
|
03/06/2023
|
#57447
|
wp_ajax_inline_save function does not check if post has "public" or "show_ui" enabled
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
01/11/2023
|
#57424
|
Specific hook for Content Security Policy
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
01/05/2023
|
#56521
|
wp_kses wp_kses_hair fails to allow a valueless attribute when is follwed by /
|
|
has-patch
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
09/06/2022
|
#40237
|
Educate users about modern password best-practices
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
06/06/2022
|
#51438
|
Use CSP directive upgrade-insecure-requests when using HTTPS
|
|
needs-unit-tests
|
normal
|
normal
|
Future Release
|
enhancement
|
11/09/2021
|
#53994
|
REST API requests with session cookies but an invalid/missing nonce are considered authenticated for most of the request
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
08/24/2021
|
#53869
|
Post type / Taxonomy Label Hardening: Prevent Raw HTML tags in output / Media Library eval of HTML entities in label
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
08/04/2021
|
#23165
|
Admin validation errors on form nonce element IDs (_wpnonce)
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
02/08/2021
|
#52333
|
Lack of the : entity on the list of allowed entity names in kses.php
|
|
has-patch
|
normal
|
minor
|
Awaiting Review
|
defect (bug)
|
01/20/2021
|
#51611
|
Escape echoing Core functions
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
10/24/2020
|
#36087
|
Migration plan from insecure RNG fallback
|
|
|
normal
|
normal
|
Future Release
|
enhancement
|
09/30/2020
|
#31686
|
wp_authenticate_username_password() should check for a WP_Error object
|
|
reporter-feedback
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
08/06/2019
|
#29429
|
Support frame-ancestors directive over X-Frame-Options
|
|
dev-feedback
|
normal
|
normal
|
Future Release
|
enhancement
|
07/29/2019
|
#37264
|
Please do not chmod 666 the wp-config.php file on installation.
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
03/22/2019
|
#44058
|
Include security sniffs in PHPCS ruleset
|
|
|
normal
|
normal
|
Future Release
|
enhancement
|
05/16/2018
|
#43320
|
Harden API requests against man-in-the-middle attacks
|
|
|
low
|
minor
|
Awaiting Review
|
enhancement
|
02/18/2018
|
#41391
|
Links to media in password protected pages
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
07/24/2017
|