[wp-trac] [WordPress Trac] #63866: Always sanitize the first parameter of wp_verify_nonce

WordPress Trac noreply at wordpress.org
Mon Aug 25 16:02:31 UTC 2025


#63866: Always sanitize the first parameter of wp_verify_nonce
-------------------------+----------------------
 Reporter:  davidperez   |       Owner:  (none)
     Type:  enhancement  |      Status:  closed
 Priority:  normal       |   Milestone:
Component:  Security     |     Version:
 Severity:  normal       |  Resolution:  wontfix
 Keywords:  2nd-opinion  |     Focuses:
-------------------------+----------------------

Comment (by davidperez):

 Hello,
 I understand the backwards compatibility for unslash, but not for
 sanitizing. We have the Plugin Check plugin to prevent developers from
 using the code incorrectly, so we could avoid double sanitization over
 time.

 Thanks for your explanation.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/63866#comment:7>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list