[wp-trac] [WordPress Trac] #58336: Potential XSS on admin_body_class hook

WordPress Trac noreply at wordpress.org
Thu May 25 15:33:34 UTC 2023


#58336: Potential XSS on admin_body_class hook
--------------------------+-----------------------------
 Reporter:  rafiem        |       Owner:  SergeyBiryukov
     Type:  defect (bug)  |      Status:  reopened
 Priority:  normal        |   Milestone:  6.3
Component:  Security      |     Version:
 Severity:  normal        |  Resolution:
 Keywords:                |     Focuses:
--------------------------+-----------------------------

Comment (by desrosj):

 Just adding a bit of history for full context to the front end changes. It
 looks like late escaping was added for body and post classes in WP 5.5
 through #20009/[48060]. There was also a follow up
 [https://github.com/WordPress/WordPress-Coding-Standards/issues/746 in
 WPCS].

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/58336#comment:12>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list