From 58440ac942dfa82fad9081f0663ef064cb4a7b6a Mon Sep 17 00:00:00 2001 From: Jeremy Felt Date: Mon, 6 Mar 2017 08:11:19 +0000 Subject: [PATCH] Validate video and audio metadata. Merge of [40148] to the 4.0 branch. Built from https://develop.svn.wordpress.org/branches/4.0@40156 git-svn-id: http://core.svn.wordpress.org/branches/4.0@40095 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-admin/includes/media.php | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/wp-admin/includes/media.php b/wp-admin/includes/media.php index 7caa2fc973..b20f1465ac 100644 --- a/wp-admin/includes/media.php +++ b/wp-admin/includes/media.php @@ -2945,6 +2945,8 @@ function wp_read_video_metadata( $file ) { wp_add_id3_tag_data( $metadata, $data ); + $metadata = wp_kses_post_deep( $metadata ); + return $metadata; } @@ -2984,5 +2986,7 @@ function wp_read_audio_metadata( $file ) { wp_add_id3_tag_data( $metadata, $data ); + $metadata = wp_kses_post_deep( $metadata ); + return $metadata; }