From 2fd80efe13356e88aab27ff9b9ccbaf96ebb86af Mon Sep 17 00:00:00 2001 From: Sergey Biryukov Date: Fri, 20 Mar 2020 02:20:08 +0000 Subject: [PATCH] Administration: Escape admin title on output after the `admin_title` filter runs, not before. Props lalitpendhare, adnan.limdi, subrataemfluence, andraganescu. Fixes #41921. Built from https://develop.svn.wordpress.org/trunk@47474 git-svn-id: http://core.svn.wordpress.org/trunk@47261 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-admin/admin-header.php | 8 ++++---- wp-admin/customize.php | 2 +- wp-includes/version.php | 2 +- 3 files changed, 6 insertions(+), 6 deletions(-) diff --git a/wp-admin/admin-header.php b/wp-admin/admin-header.php index 40ac51cf29..c6760f9b86 100644 --- a/wp-admin/admin-header.php +++ b/wp-admin/admin-header.php @@ -32,14 +32,14 @@ if ( empty( $current_screen ) ) { } get_admin_page_title(); -$title = esc_html( strip_tags( $title ) ); +$title = strip_tags( $title ); if ( is_network_admin() ) { /* translators: Network admin screen title. %s: Network title. */ - $admin_title = sprintf( __( 'Network Admin: %s' ), esc_html( get_network()->site_name ) ); + $admin_title = sprintf( __( 'Network Admin: %s' ), get_network()->site_name ); } elseif ( is_user_admin() ) { /* translators: User dashboard screen title. %s: Network title. */ - $admin_title = sprintf( __( 'User Dashboard: %s' ), esc_html( get_network()->site_name ) ); + $admin_title = sprintf( __( 'User Dashboard: %s' ), get_network()->site_name ); } else { $admin_title = get_bloginfo( 'name' ); } @@ -71,7 +71,7 @@ wp_user_settings(); _wp_admin_html_begin(); ?> -<?php echo $admin_title; ?> +<?php echo esc_html( $admin_title ); ?> get_document_title_template(), __( 'Loading…' ) ); ?> -<?php echo $admin_title; ?> +<?php echo esc_html( $admin_title ); ?>