[wp-trac] [WordPress Trac] #52894: The wp_sanitize_script_attributes function added in version 5.7 does not escape attributes in some cases.

WordPress Trac noreply at wordpress.org
Wed Mar 24 02:49:12 UTC 2021


#52894: The wp_sanitize_script_attributes function added in version 5.7 does not
escape attributes in some cases.
---------------------------+---------------------
 Reporter:  tmatsuur       |       Owner:  (none)
     Type:  defect (bug)   |      Status:  new
 Priority:  normal         |   Milestone:  5.7.1
Component:  Script Loader  |     Version:  5.7
 Severity:  critical       |  Resolution:
 Keywords:  has-patch      |     Focuses:
---------------------------+---------------------

Comment (by joyously):

 Fine, but that is still escaping, not sanitizing. Some of those characters
 are not valid for attributes.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/52894#comment:4>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list