[wp-trac] [WordPress Trac] #24775: Revisions: Make sure our templating is properly escaped

WordPress Trac noreply at wordpress.org
Wed Jul 17 20:34:06 UTC 2013


#24775: Revisions: Make sure our templating is properly escaped
----------------------------+--------------------
 Reporter:  markjaquith     |       Owner:
     Type:  task (blessed)  |      Status:  new
 Priority:  normal          |   Milestone:  3.6
Component:  Security        |     Version:  trunk
 Severity:  normal          |  Resolution:
 Keywords:                  |
----------------------------+--------------------

Comment (by nacin):

 I think {{{ to {{ for restoreUrl requires us to undo & => & that is
 done by wp_nonce_url()? I can't tell if it just accidentally works, or if
 {{ deliberately doesn't re-escape &

--
Ticket URL: <http://core.trac.wordpress.org/ticket/24775#comment:2>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list