[wp-trac] [WordPress Trac] #33848: Protect against vulnerability in Netscape 4?

WordPress Trac noreply at wordpress.org
Sun Dec 6 18:26:33 UTC 2015


#33848: Protect against vulnerability in Netscape 4?
-------------------------+------------------------------
 Reporter:  dmsnell      |       Owner:
     Type:  enhancement  |      Status:  new
 Priority:  normal       |   Milestone:  Awaiting Review
Component:  Security     |     Version:  4.4
 Severity:  normal       |  Resolution:
 Keywords:               |     Focuses:  performance
-------------------------+------------------------------

Comment (by pento):

 Note that
 [https://github.com/search?q=wp_kses_js_entities&type=Code&utf8=%E2%9C%93
 a lot of plugins] use `wp_kses_js_entities()`, so a patch can only remove
 calls to the function, the function itself needs to stay (probably in
 `kses.php`, too, for anything that loads KSES directly).

--
Ticket URL: <https://core.trac.wordpress.org/ticket/33848#comment:6>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list