Plugin Directory

Changeset 2492534


Ignore:
Timestamp:
03/10/2021 06:45:30 PM (5 years ago)
Author:
akirak
Message:

use wp_kses for sanitizing

File:
1 edited

Legend:

Unmodified
Added
Removed
  • custom-global-variables/trunk/custom-global-variables.php

    r2492226 r2492534  
    9595            foreach ( $_POST['vars'] as $var ) {
    9696                $var['name'] = sanitize_textarea_field($var['name']);
     97                $var['val'] = wp_kses_post($var['val']);
     98
    9799
    98100                if ( ! empty( $var['name'] ) && !empty( $var['val'] ) ) {
     
    155157                                    <?php
    156158                                    $key = esc_html($key);
     159                                    $val = wp_kses_post($val);
    157160                                    ?>
    158161
     
    220223        $param0 = sanitize_text_field($params[0]);
    221224        if ( ! empty( $GLOBALS['cgv'][ $param0 ])  ) {
    222             return $GLOBALS['cgv'][ $param0 ];
     225            return wp_kses_post($GLOBALS['cgv'][ $param0 ]);
    223226        }
    224227
Note: See TracChangeset for help on using the changeset viewer.