Not escaped WP core functions
-
Hi,
Why are functions like the_archive_title() and the_archive_description() used by a lot of themes (e.g. Twenty Seventeen, Twenty Nineteen) in archive.php without escaping, although it looks like there is no proper output escaping in WP core?
In wp-admin/profile.php the display_name and the author_meta(‘description’) are stored from user input – which will be output in archive.php if is_author(), by these functions – without escaping.Best regards
Max L.
Viewing 9 replies - 1 through 9 (of 9 total)
Viewing 9 replies - 1 through 9 (of 9 total)
- The topic ‘Not escaped WP core functions’ is closed to new replies.