Make WordPress Core

Opened 6 years ago

Last modified 6 years ago

#20210 closed defect (bug)

Always allow the standard attributes for all elements when filtering content using kses for posts. — at Version 2

Reported by: westi Owned by:
Milestone: 3.5 Priority: normal
Severity: normal Version: 3.4
Component: Formatting Keywords: needs-patch
Focuses: Cc:

Description (last modified by westi)

The list of allowed attributes to configure kses for post content filtering is hit and miss.

We should always allow the standard attributes: class, id, style and title.

We should also make any other extend attributes consistent.

Related: #18649, #18133 / #17977

Change History (2)

#1 @westi
6 years ago

[UT569] is a start on some tests for these kind of issues.

#2 @westi
6 years ago

  • Description modified (diff)
Note: See TracTickets for help on using tickets.