Only run stripslashes() on strings in update_usermeta(). Props stm. fixes #3240
git-svn-id: http://svn.automattic.com/wordpress/branches/2.0@4395 1a063a9b-81f0-0310-95a4-ce76da25c4cd
This commit is contained in:
parent
6651c29d96
commit
2d8ad48991
|
@ -2278,6 +2278,7 @@ function update_usermeta( $user_id, $meta_key, $meta_value ) {
|
|||
$meta_key = preg_replace('|[^a-z0-9_]|i', '', $meta_key);
|
||||
|
||||
// FIXME: usermeta data is assumed to be already escaped
|
||||
if ( is_string($meta_value) )
|
||||
$meta_value = stripslashes($meta_value);
|
||||
$meta_value = maybe_serialize($meta_value);
|
||||
$meta_value = $wpdb->escape($meta_value);
|
||||
|
|
Loading…
Reference in New Issue