[wp-trac] [WordPress Trac] #30967: $fallback in sanitize_html_class() is not sanitized

WordPress Trac noreply at wordpress.org
Fri Jan 9 20:12:00 UTC 2015


#30967: $fallback in sanitize_html_class() is not sanitized
-------------------------------+------------------------------
 Reporter:  mighty_mt          |       Owner:
     Type:  defect (bug)       |      Status:  new
 Priority:  normal             |   Milestone:  Awaiting Review
Component:  Posts, Post Types  |     Version:  trunk
 Severity:  normal             |  Resolution:
 Keywords:                     |     Focuses:
-------------------------------+------------------------------

Comment (by mighty_mt):

 @[comment:1 MikeHansenMe]: Sure the sanitized fallback might end up being
 empty too but I think that's better than returning an invalid CSS class
 name.

 By the way, I just quickly did a full text search of all PHP files in the
 ''wp-incudes'' directory and found that there are a few places in core
 where the fallback is used... once in the {{{get_comment_class()}}}
 function and multiple times in {{{get_post_class()}}}. See also #30883.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/30967#comment:2>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list