[wp-trac] [WordPress Trac] #62797: wp_add_inline_script does not properly escape '<!-- <script>' in contents

WordPress Trac noreply at wordpress.org
Wed Aug 13 08:21:59 UTC 2025


#62797: wp_add_inline_script does not properly escape '<!-- <script>' in contents
-------------------------------------------------+-------------------------
 Reporter:  artpi                                |       Owner:  jonsurrell
     Type:  defect (bug)                         |      Status:  accepted
 Priority:  normal                               |   Milestone:  6.9
Component:  Editor                               |     Version:  5.0
 Severity:  normal                               |  Resolution:
 Keywords:  has-patch has-unit-tests dev-        |     Focuses:
  feedback                                       |  administration
-------------------------------------------------+-------------------------
Changes (by jonsurrell):

 * owner:  (none) => jonsurrell
 * status:  new => accepted


Comment:

 This is a complex problem that [https://sirre.al/2025/08/06/safe-json-in-
 script-tags-how-not-to-break-a-site/ I investigated and wrote about in
 detail here] for folks that are interested in understanding exactly what's
 happening and the background.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/62797#comment:23>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list