[wp-trac] [WordPress Trac] #15086: get_template_part() should let you specify a directory

WordPress Trac wp-trac at lists.automattic.com
Sun Oct 10 22:12:33 UTC 2010


#15086: get_template_part() should let you specify a directory
---------------------------+------------------------------------------------
 Reporter:  aaroncampbell  |       Owner:                 
     Type:  enhancement    |      Status:  new            
 Priority:  normal         |   Milestone:  Awaiting Review
Component:  Themes         |     Version:  3.0            
 Severity:  normal         |    Keywords:  dev-feedback   
---------------------------+------------------------------------------------

Comment(by scribu):

 get_template_part() should not be alowed to look outside the current theme
 directory.

 Maybe we should just sanitize it so that it allows 'directory/slug', but
 not '../slug'.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/15086#comment:2>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list