[wp-trac] [WordPress Trac] #44434: oEmbed start pulling in iframes from any websites

WordPress Trac noreply at wordpress.org
Mon Jun 25 11:07:14 UTC 2018


#44434: oEmbed start pulling in iframes from any websites
--------------------------+-------------------------
 Reporter:  drivdigital   |       Owner:  (none)
     Type:  defect (bug)  |      Status:  closed
 Priority:  normal        |   Milestone:
Component:  Embeds        |     Version:  4.9.6
 Severity:  normal        |  Resolution:  worksforme
 Keywords:  close         |     Focuses:
--------------------------+-------------------------

Comment (by azaozz):

 Replying to [comment:7 drivdigital]:
 > Is it worth suggesting a way for disabling oEmbeds without a plugin?

 It's not that simple :) We can add another setting (somewhere) to disable
 support for oEmbeds, but it would be somewhat misleading. Admins and
 Editors can paste "unfiltered HTML", so they will still be able to paste
 any embedded code in any post or text widget. Then again, adding yet
 another setting to disable functionality that has been in WP for many
 years is probably best left for a plugin.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/44434#comment:9>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list