WordPress/wp-admin
Sergey Biryukov 045c01e20b Escape the output in `wp_ajax_upload_attachment()`.
Merges [45936] to the 5.0 branch.
Props whyisjake, sstoqnov.
Built from https://develop.svn.wordpress.org/branches/5.0@45941


git-svn-id: http://core.svn.wordpress.org/branches/5.0@45752 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 16:26:48 +00:00
..
css Block Editor: Display notice to the user when JavaScript is disabled. 2019-01-07 20:59:45 +00:00
images Build: Update images following [43684]. 2018-10-22 05:06:38 +00:00
includes Escape the output in `wp_ajax_upload_attachment()`. 2019-09-04 16:26:48 +00:00
js Docs: Future-proof comments referencing 5.0 TODOs. 2018-11-12 04:23:48 +00:00
maint
network General: Replace `Cheatin’ uh?` with friendlier error messages. 2018-03-09 00:15:42 +00:00
user Administration: Ensure the new Privacy Policy screen appears when within the Network Admin and User Admin. 2017-11-06 18:17:54 +00:00
about.php WordPress 5.0.5 2019-03-13 00:35:46 +00:00
admin-ajax.php Dashboard: Remove the Try Gutenberg callout. 2018-10-23 11:04:40 +00:00
admin-footer.php Docs: Remove incorrect `@param` tags for `admin_print_footer_scripts-{$hook_suffix}` and `admin_footer-{$hook_suffix}` dynamic actiona. 2017-01-09 14:38:41 +00:00
admin-functions.php
admin-header.php Block Editor: Add extra body classes when the block editor is loaded. 2018-10-22 03:14:40 +00:00
admin-post.php
admin.php Transients: After [41963], add missing cron task for `delete_expired_transients()`. 2017-10-24 23:00:47 +00:00
async-upload.php Escape the output in `wp_ajax_upload_attachment()`. 2019-09-04 16:26:48 +00:00
comment.php
credits.php Help/About: Add copy for new block editor. 2018-11-22 15:24:45 +00:00
custom-background.php Docs: Remove `@access` notations from method DocBlocks in wp-admin/* classes. 2017-07-27 00:40:43 +00:00
custom-header.php General: Replace `Cheatin’ uh?` with friendlier error messages. 2018-03-09 00:15:42 +00:00
customize.php General: Replace `Cheatin’ uh?` with friendlier error messages. 2018-03-09 00:15:42 +00:00
edit-comments.php General: Replace `Cheatin’ uh?` with friendlier error messages. 2018-03-09 00:15:42 +00:00
edit-form-advanced.php Block Editor: Fix meta boxes not showing. 2018-10-29 08:29:23 +00:00
edit-form-blocks.php Block Editor: Display notice to the user when JavaScript is disabled. 2019-01-07 20:59:45 +00:00
edit-form-comment.php Block Editor: Fix meta boxes not showing. 2018-10-29 08:29:23 +00:00
edit-link-form.php Block Editor: Fix meta boxes not showing. 2018-10-29 08:29:23 +00:00
edit-tag-form.php Taxonomy: Introduce a `back_to_items` taxonomy label. 2017-09-27 14:39:45 +00:00
edit-tags.php General: Replace `Cheatin’ uh?` with friendlier error messages. 2018-03-09 00:15:42 +00:00
edit.php Block Editor: Fix the WordPress packages and vendor script registration. 2018-11-23 08:35:45 +00:00
export.php
freedoms.php About: Update Freedoms page to include illustrations. 2018-11-22 18:03:45 +00:00
import.php
index.php Dashboard: Remove the Try Gutenberg callout. 2018-10-23 11:04:40 +00:00
install-helper.php
install.php I18N: Allow numbers in locales during installation. 2017-09-04 19:30:43 +00:00
link-add.php
link-manager.php Accessibility: Remove inappropriate content from the Link Manager screens headings. 2016-12-07 20:18:46 +00:00
link-parse-opml.php
link.php
load-scripts.php Script Loader: Ensure default packages are registered when loaded via load-scripts.php. 2018-11-08 09:24:51 +00:00
load-styles.php Script loader: remove (PHP based) compression from `load-styles.php` and `load-scripts.php`. WIth the amount of scripts and stylesheets grown a lot over the years, it has become pretty slow and consumes a lot of server resources. Also, most servers are set to compress PHP output anyway. 2018-10-11 03:23:22 +00:00
media-new.php
media-upload.php General: Replace `Cheatin’ uh?` with friendlier error messages. 2018-03-09 00:15:42 +00:00
media.php Accessibility: Remove inappropriate content from the old Edit Media screen heading. 2016-12-07 23:30:40 +00:00
menu-header.php Administration: Admin menu: Use `aria-current` for the current active page. 2017-09-09 14:50:43 +00:00
menu.php Privacy: Replace intrusive policy update notice with menu bubbles. 2018-05-10 20:08:26 +00:00
moderation.php
ms-admin.php
ms-delete-site.php I18N: Unify permission error message in `wp-admin/ms-delete-site.php`. 2017-10-19 00:48:50 +00:00
ms-edit.php
ms-options.php
ms-sites.php
ms-themes.php
ms-upgrade-network.php
ms-users.php
my-sites.php Users: Remove some links to the dashboard from My Sites for users who cannot access it. 2017-10-09 15:22:46 +00:00
nav-menus.php Update `sidebars_widgets` to match Twenty Nineteen's single widget area 2018-11-30 20:25:46 +00:00
network.php General: Improve terminology used when referring to installations of WordPress and its extensions. 2017-08-22 11:52:48 +00:00
options-discussion.php Privacy: Revert [43525]. 2018-07-24 17:08:26 +00:00
options-general.php Role/Capability: Make `install_languages` capability check less restrictive. 2018-01-24 22:59:38 +00:00
options-head.php
options-media.php Media: On Media Settings screen, make the pairs of labels and inputs always stacked vertically, on both mobile and desktop screens. 2018-03-20 22:49:39 +00:00
options-permalink.php Permalinks: Change mention of URI to URL in the description of `%category%` tag. 2017-10-25 11:11:45 +00:00
options-reading.php Customize: Rename "Static front page" to just "Homepage". 2017-09-10 16:20:44 +00:00
options-writing.php I18N: Remove `<code>` and `<kbd>` tags from translatable strings on Settings screens. 2017-10-24 10:51:52 +00:00
options.php Privacy: Revert [43525]. 2018-07-24 17:08:26 +00:00
plugin-editor.php Code Editors: Update copy in warning modals. 2017-10-24 18:47:47 +00:00
plugin-install.php General: Improve terminology used when referring to installations of WordPress and its extensions. 2017-08-22 11:52:48 +00:00
plugins.php Dashboard: Remove the Try Gutenberg callout. 2018-10-23 11:04:40 +00:00
post-new.php Editor: Minor bug fixes. 2018-10-24 06:46:40 +00:00
post.php Block Editor: Display notice to the user when JavaScript is disabled. 2019-01-07 20:59:45 +00:00
press-this.php General: Replace `Cheatin’ uh?` with friendlier error messages. 2018-03-09 00:15:42 +00:00
privacy.php Privacy: Improve grammar on Privacy Settings screen. 2018-07-19 20:16:26 +00:00
profile.php
revision.php
setup-config.php I18N: Replace hardcoded file name in translatable strings in `wp-admin/setup-config.php` with a placeholder. 2017-10-18 15:27:53 +00:00
term.php General: Replace `Cheatin’ uh?` with friendlier error messages. 2018-03-09 00:15:42 +00:00
theme-editor.php Theme Editor: Translate the URL to the Child Themes Codex page. 2017-11-27 03:53:40 +00:00
theme-install.php Themes: Improve line wrapping in feature filter on Theme Install screen and in the Customizer. 2018-01-15 19:30:40 +00:00
themes.php General: Replace `Cheatin’ uh?` with friendlier error messages. 2018-03-09 00:15:42 +00:00
tools.php Privacy: show the privacy policy guide and suggested content on a new page instead of a postbox. Then: 2018-05-09 21:00:28 +00:00
update-core.php Plugins: Tweak the plugin icons added in [41695]. 2017-10-04 23:43:46 +00:00
update.php Customize: Eliminate use of customize-loader in core so Customizer is opened consistently in `top` window. 2017-10-09 16:04:48 +00:00
upgrade-functions.php
upgrade.php
upload.php Accessibility: Improve the Media Library inline uploader accessibility. 2017-03-31 17:38:43 +00:00
user-edit.php Taxonomy/Users: Use correct escaping function for URLs. 2017-09-19 21:14:47 +00:00
user-new.php General: Replace `Cheatin’ uh?` with friendlier error messages. 2018-03-09 00:15:42 +00:00
users.php General: Replace `Cheatin’ uh?` with friendlier error messages. 2018-03-09 00:15:42 +00:00
widgets.php General: Replace `Cheatin’ uh?` with friendlier error messages. 2018-03-09 00:15:42 +00:00