[wp-trac] [WordPress Trac] #56145: unescaped 'home_url()' in 'wp-admin/themes.php' file in 'line 269'

WordPress Trac noreply at wordpress.org
Tue Jul 5 14:24:16 UTC 2022


#56145: unescaped 'home_url()' in 'wp-admin/themes.php' file in 'line 269'
-----------------------------------------+-----------------------------
 Reporter:  obayedmamur                  |       Owner:  (none)
     Type:  defect (bug)                 |      Status:  new
 Priority:  normal                       |   Milestone:  6.1
Component:  Themes                       |     Version:
 Severity:  normal                       |  Resolution:
 Keywords:  has-patch changes-requested  |     Focuses:  administration
-----------------------------------------+-----------------------------

Comment (by hurayraiit):

 Replying to [comment:5 desrosj]:
 > @hurayraiit It looks like there is a second instance of `home_url()` not
 being wrapped with `esc_url()` that [attachment:"56145.patch"] fixes, but
 the one mentioned in the original ticket title is not corrected.
 >
 > Could you change both at the same time in one patch?

 Yeah, absolutely. Let me check please.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/56145#comment:7>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list