[wp-trac] Re: [WordPress Trac] #3991: Default theme allows markup in titles

WordPress Trac wp-trac at lists.automattic.com
Sun Mar 18 14:39:15 GMT 2007


#3991: Default theme allows markup in titles
----------------------+-----------------------------------------------------
 Reporter:  elharo    |        Owner:  anonymous
     Type:  defect    |       Status:  new      
 Priority:  normal    |    Milestone:  2.1.3    
Component:  Security  |      Version:  2.1.2    
 Severity:  normal    |   Resolution:           
 Keywords:            |  
----------------------+-----------------------------------------------------
Changes (by mikewp):

  * component:  Template => Security

Comment:

 Markup shouldn't be allowed in the title. The styling can be done via CSS.

 I've attached a patch. It adds a htmlentities filter for the title before
 wptexturize

-- 
Ticket URL: <http://trac.wordpress.org/ticket/3991#comment:1>
WordPress Trac <http://trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list