Privacy: Pass admin URLs for data export and erase forms through `esc_url()`.
Introduced in [45149]. Props: birgire. Fixes #44047. Built from https://develop.svn.wordpress.org/trunk@45154 git-svn-id: http://core.svn.wordpress.org/trunk@44963 1a063a9b-81f0-0310-95a4-ce76da25c4cd
This commit is contained in:
parent
33c82208a2
commit
dd0785d3f9
|
@ -830,7 +830,7 @@ function _wp_personal_data_export_page() {
|
|||
|
||||
<?php settings_errors(); ?>
|
||||
|
||||
<form action="<?php echo admin_url( 'tools.php?page=export_personal_data' ); ?>" method="post" class="wp-privacy-request-form">
|
||||
<form action="<?php echo esc_url( admin_url( 'tools.php?page=export_personal_data' ) ); ?>" method="post" class="wp-privacy-request-form">
|
||||
<h2><?php esc_html_e( 'Add Data Export Request' ); ?></h2>
|
||||
<p><?php esc_html_e( 'An email will be sent to the user at this email address asking them to verify the request.' ); ?></p>
|
||||
|
||||
|
@ -914,7 +914,7 @@ function _wp_personal_data_removal_page() {
|
|||
|
||||
<?php settings_errors(); ?>
|
||||
|
||||
<form action="<?php echo admin_url( 'tools.php?page=remove_personal_data' ); ?>" method="post" class="wp-privacy-request-form">
|
||||
<form action="<?php echo esc_url( admin_url( 'tools.php?page=remove_personal_data' ) ); ?>" method="post" class="wp-privacy-request-form">
|
||||
<h2><?php esc_html_e( 'Add Data Erasure Request' ); ?></h2>
|
||||
<p><?php esc_html_e( 'An email will be sent to the user at this email address asking them to verify the request.' ); ?></p>
|
||||
|
||||
|
|
|
@ -13,7 +13,7 @@
|
|||
*
|
||||
* @global string $wp_version
|
||||
*/
|
||||
$wp_version = '5.2-beta2-45153';
|
||||
$wp_version = '5.2-beta2-45154';
|
||||
|
||||
/**
|
||||
* Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.
|
||||
|
|
Loading…
Reference in New Issue