Make WordPress Core

Opened 15 years ago

Closed 15 years ago

#9322 closed defect (bug) (fixed)

Post/Page titles aren't fully escaped

Reported by: viper007bond's profile Viper007Bond Owned by:
Milestone: 2.8 Priority: normal
Severity: normal Version: 2.8
Component: Administration Keywords: has-patch needs-testing
Focuses: Cc:


To reproduce:

  1. Write a post called "I &lt;3 WordPress". Note you cannot use "<" as HTML is currently allowed in post titles (<del> for example is a valid usage).

  1. Save or Publish the post. You'll notice the title of the post is now "I <3 WordPress". This is incorrect and will break things if you save again.

Attached patch fully escapes all post titles.

Attachments (2)

9322.patch (768 bytes) - added by Viper007Bond 15 years ago.
9322.2.patch (770 bytes) - added by Viper007Bond 15 years ago.

Download all attachments as: .zip

Change History (6)

15 years ago

#1 @Viper007Bond
15 years ago

Bad patch. Quotes and things now improperly get escaped.

#2 @Viper007Bond
15 years ago

There, working as intended now (I think).

#3 @azaozz
15 years ago

  • Milestone changed from Future Release to 2.8

#4 @azaozz
15 years ago

  • Resolution set to fixed
  • Status changed from new to closed

(In [10787]) Fully escape Post/Page titles, props Viper007Bond, fixes #9322

Note: See TracTickets for help on using tickets.