[wp-trac] [WordPress Trac] #62797: wp_add_inline_script does not properly escape '<!-- <script>' in contents

WordPress Trac noreply at wordpress.org
Fri Jan 10 21:02:37 UTC 2025


#62797: wp_add_inline_script does not properly escape '<!-- <script>' in contents
-------------------------------------+------------------------------
 Reporter:  artpi                    |       Owner:  (none)
     Type:  defect (bug)             |      Status:  new
 Priority:  normal                   |   Milestone:  Awaiting Review
Component:  Editor                   |     Version:  5.0
 Severity:  normal                   |  Resolution:
 Keywords:  has-patch needs-testing  |     Focuses:  administration
-------------------------------------+------------------------------
Changes (by jonsurrell):

 * version:  6.7.1 => 5.0


Comment:

 [https://github.com/WordPress/WordPress/blob/491c67be12ca8a9fe37ae38307ba7e298c976ec3
 /wp-admin/edit-form-blocks.php#L85-L89 The issue has been present in some
 form since 5.0].

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/62797#comment:6>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list