[wp-trac] [WordPress Trac] #14601: wp_new_comment method doesn't allow passed in values for IP and user-agent

WordPress Trac noreply at wordpress.org
Thu Jun 4 16:21:32 UTC 2015


#14601: wp_new_comment method doesn't allow passed in values for IP and user-agent
--------------------------------+--------------------------
 Reporter:  mrutz               |       Owner:  rachelbaker
     Type:  enhancement         |      Status:  accepted
 Priority:  normal              |   Milestone:  4.3
Component:  Comments            |     Version:  3.0.1
 Severity:  normal              |  Resolution:
 Keywords:  rest-api has-patch  |     Focuses:
--------------------------------+--------------------------

Comment (by boonebgorges):

 I'd like to see an answer to [comment:12 nacin's comment] regarding
 whether WP, or any plugins, are passing `$_POST` data (or some other
 unsanitized array) directly to `wp_new_comment()`. Can someone search the
 plugin directory to get a sense of what's out there in the wild?

--
Ticket URL: <https://core.trac.wordpress.org/ticket/14601#comment:26>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list