[wp-trac] [WordPress Trac] #24672: Remove final from WP_Post class

WordPress Trac noreply at wordpress.org
Wed Mar 28 20:53:03 UTC 2018


#24672: Remove final from WP_Post class
-------------------------------+------------------------------
 Reporter:  carlalexander      |       Owner:
     Type:  enhancement        |      Status:  reopened
 Priority:  normal             |   Milestone:  Awaiting Review
Component:  Posts, Post Types  |     Version:  3.5
 Severity:  normal             |  Resolution:
 Keywords:  2nd-opinion        |     Focuses:
-------------------------------+------------------------------

Comment (by jorbin):

 What happens when a plugin adds a method that returns unescaped data and
 handles the escaping later and later core adds a method with the same name
 where it is returned escaped?  A 2nd plugin using that method could
 introduce a security vulnerability since it assumes the data is escaped by
 core.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/24672#comment:21>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list