[wp-trac] [WordPress Trac] #37208: Comment blacklist can be bypassed with HTML

WordPress Trac noreply at wordpress.org
Thu Jul 14 15:06:40 UTC 2016


#37208: Comment blacklist can be bypassed with HTML
--------------------------------------+--------------------------
 Reporter:  cfinke                    |       Owner:  rachelbaker
     Type:  defect (bug)              |      Status:  reopened
 Priority:  normal                    |   Milestone:  4.6
Component:  Comments                  |     Version:  1.5
 Severity:  normal                    |  Resolution:
 Keywords:  has-unit-tests has-patch  |     Focuses:
--------------------------------------+--------------------------
Changes (by rachelbaker):

 * keywords:  has-unit-tests needs-patch => has-unit-tests has-patch


Comment:

 @dd32 Thanks for catching this.  Added [attachment:37208_strip_tags.diff]
 patch that uses `wp_strip_all_tags()`

--
Ticket URL: <https://core.trac.wordpress.org/ticket/37208#comment:11>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list