[wp-trac] [WordPress Trac] #22436: escape recent posts widget post titles

WordPress Trac noreply at wordpress.org
Wed Nov 14 02:45:28 UTC 2012


#22436: escape recent posts widget post titles
-----------------------------+--------------------------
 Reporter:  niallkennedy     |       Type:  defect (bug)
   Status:  new              |   Priority:  normal
Milestone:  Awaiting Review  |  Component:  Widgets
  Version:                   |   Severity:  normal
 Keywords:  has-patch        |
-----------------------------+--------------------------
 The recent posts widget escapes the title attribute but does not escape
 element text. Add an esc_html wrapper to post title values to escape
 before output.

 Example post title: Post about < stuff >

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/22436>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list