[wp-trac] [WordPress Trac] #62797: wp_add_inline_script does not properly escape '<!-- <script>' in contents

WordPress Trac noreply at wordpress.org
Fri Jan 10 01:54:35 UTC 2025


#62797: wp_add_inline_script does not properly escape '<!-- <script>' in contents
--------------------------+------------------------------
 Reporter:  artpi         |       Owner:  (none)
     Type:  defect (bug)  |      Status:  new
 Priority:  normal        |   Milestone:  Awaiting Review
Component:  Editor        |     Version:  6.7.1
 Severity:  normal        |  Resolution:
 Keywords:                |     Focuses:
--------------------------+------------------------------

Comment (by ankitkumarshah):

 == Reproduction Report
 === Description
 This report validates whether the issue can be reproduced.

 === Environment
 - WordPress: 6.8-alpha-59593
 - PHP: 8.1.29
 - Server: nginx/1.16.0
 - Database: mysqli (Server: 8.0.16 / Client: mysqlnd 8.1.29)
 - Browser: Chrome 131.0.0.0
 - OS: macOS
 - Theme: Twenty Seventeen 3.8
 - MU Plugins: None activated
 - Plugins:
   * Gutenslider — The last WordPress slider you will ever need. 6.1.0
   * Test Plugin
   * Test Reports 1.2.0
   * WordPress Beta Tester 3.6.2

 === Actual Results
 ✅ Error condition occurs (reproduced).
 Hi @artpi,

 Thank you for bringing this up. By following the provided steps, I
 reproduced the issue successfully.

 === Screencast

 https://ppgtp1rtd3.ufs.sh/f/TnWMEUzoUd85Fb83cfTuejSJhDdioPMH6NAwRtYmfvQBT3W9

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/62797#comment:1>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list