[wp-trac] [WordPress Trac] #17780: Use PHP native double encoding prevention in htmlspecialchars()

WordPress Trac noreply at wordpress.org
Mon Jul 13 02:44:52 UTC 2015


#17780: Use PHP native double encoding prevention in htmlspecialchars()
----------------------------------------+--------------------------
 Reporter:  nbachiyski                  |       Owner:  miqrogroove
     Type:  defect (bug)                |      Status:  reopened
 Priority:  high                        |   Milestone:  4.3
Component:  Formatting                  |     Version:
 Severity:  major                       |  Resolution:
 Keywords:  needs-unit-tests has-patch  |     Focuses:
----------------------------------------+--------------------------

Comment (by miqrogroove):

 I'd like to see the patch in beta 3.  If you really think this is going to
 cause some damage then the right thing to do here may be to deprecate
 esc_attr() and replace it with a corrected function.  And that wouldn't be
 ready for one or two versions for sure.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/17780#comment:39>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list