[wp-trac] Re: [WordPress Trac] #3243: Usermeta and postmeta functions assume data to be pre-escaped

WordPress Trac wp-trac at lists.automattic.com
Sat Jun 13 22:57:35 GMT 2009


#3243: Usermeta and postmeta functions assume data to be pre-escaped
----------------------------+-----------------------------------------------
 Reporter:  markjaquith     |       Owner:  markjaquith
     Type:  task (blessed)  |      Status:  accepted   
 Priority:  high            |   Milestone:  2.9        
Component:  Administration  |     Version:  2.1        
 Severity:  normal          |    Keywords:  close      
----------------------------+-----------------------------------------------
Changes (by Denis-de-Bernardy):

  * keywords:  needs-patch dev-feedback => close
  * priority:  normal => high


Comment:

 in *_post_meta(), I see:

 {{{
 $wpdb->update( $wpdb->postmeta, $data, $where );
 }}}

 in *_user_meta(), I see:

 {{{
 $wpdb->update($wpdb->usermeta, compact('meta_value'), compact('user_id',
 'meta_key') );
 }}}

 so presuming fixed.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/3243#comment:9>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list