Permalinks: Properly escape strings in Permalinks Settings screen.

Props jaedm97, audrasjb, robinwpdeveloper, shraboni.
Fixes #57143.

Built from https://develop.svn.wordpress.org/trunk@55331


git-svn-id: http://core.svn.wordpress.org/trunk@54864 1a063a9b-81f0-0310-95a4-ce76da25c4cd
This commit is contained in:
audrasjb 2023-02-14 11:34:23 +00:00
parent 6310d1d21a
commit 47b1864c2e
2 changed files with 11 additions and 7 deletions

View File

@ -338,15 +338,19 @@ printf(
</legend>
<?php foreach ( $default_structures as $input ) : ?>
<div class="row">
<input id="permalink-input-<?php echo $input['id']; ?>"
name="selection" aria-describedby="permalink-<?php echo $input['id']; ?>"
<input id="permalink-input-<?php echo esc_attr( $input['id'] ); ?>"
name="selection" aria-describedby="permalink-<?php echo esc_attr( $input['id'] ); ?>"
type="radio" value="<?php echo esc_attr( $input['value'] ); ?>"
<?php checked( $input['value'], $permalink_structure ); ?>
/>
<div>
<label for="permalink-input-<?php echo $input['id']; ?>"><?php echo $input['label']; ?></label>
<label for="permalink-input-<?php echo esc_attr( $input['id'] ); ?>">
<?php echo esc_html( $input['label'] ); ?>
</label>
<p>
<code id="permalink-<?php echo $input['id']; ?>"><?php echo $input['example']; ?></code>
<code id="permalink-<?php echo esc_attr( $input['id'] ); ?>">
<?php echo esc_html( $input['example'] ); ?>
</code>
</p>
</div>
</div><!-- .row -->
@ -367,7 +371,7 @@ printf(
?>
</label>
<span class="code">
<code id="permalink-custom"><?php echo $url_base; ?></code>
<code id="permalink-custom"><?php echo esc_url( $url_base ); ?></code>
<input name="permalink_structure" id="permalink_structure"
type="text" value="<?php echo esc_attr( $permalink_structure ); ?>"
aria-describedby="permalink-custom" class="regular-text code"
@ -389,7 +393,7 @@ printf(
data-added="<?php echo esc_attr( sprintf( $tag_added, $tag ) ); ?>"
data-removed="<?php echo esc_attr( sprintf( $tag_removed, $tag ) ); ?>"
data-used="<?php echo esc_attr( sprintf( $tag_already_used, $tag ) ); ?>">
<?php echo '%' . $tag . '%'; ?>
<?php echo '%' . esc_html( $tag ) . '%'; ?>
</button>
</li>
<?php endforeach; ?>

View File

@ -16,7 +16,7 @@
*
* @global string $wp_version
*/
$wp_version = '6.2-beta1-55330';
$wp_version = '6.2-beta1-55331';
/**
* Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.