Comas in photo label lead to a crash
-
Ahh too bad the pic labels do not seem to be properly escaped before saving!!!!
This is a great plugin but please use esc_attr on every user text value input. The code seems a tad weak it’s odd. update_meta(esc_attr(… shall be mandatory!
I cannot seriously consider putting this in production tomorrow (and have the customer afford a pro version) and will have to look for another portfolio plugin.
Steps to reproduce: try inputting anything between comas in the labels… crash, wipe, portfolio gone. As I said it’s just a matter of escaping stuff…
No offense taken, I just took the time for a heads up, hope this will help you.
Regards. ??
- The topic ‘Comas in photo label lead to a crash’ is closed to new replies.