Closed mfields closed 10 years ago
The following src attributes should be escaped with esc_url():
src
esc_url()
<script src="<?php echo get_template_directory_uri(); ?>/js/html5.js"></script>
<img src="<?php echo of_get_option( 'logo' ); ?>" alt="<?php echo bloginfo( 'name' ) ?>" />
<img alt="" src="' . admin_url( 'images/wpspin_light.gif' )
<img src="<?php echo get_template_directory_uri() . '/images/protected-' . $thumbnail . '.gif'; ?>">
<img src="<?php echo get_template_directory_uri() . '/images/placeholder-' . $thumbnail . '.gif'; ?>">
As well as the following href attributes:
href
echo '<link rel="shortcut icon" href="'. $favicon .'"/>
<a href="' . admin_url() . '" title="' . __( 'Return to the Dashboard', 'tgmpa' ) . '">
<a href="' . add_query_arg( ... )
admin_url()
add_query_arg( ... )
home_url()
Updated everything except items in the class-tgm-plugin-activation library. Will try to get pull requests to them for those.
The following
src
attributes should be escaped withesc_url()
:<script src="<?php echo get_template_directory_uri(); ?>/js/html5.js"></script>
<img src="<?php echo of_get_option( 'logo' ); ?>" alt="<?php echo bloginfo( 'name' ) ?>" />
<img alt="" src="' . admin_url( 'images/wpspin_light.gif' )
<img src="<?php echo get_template_directory_uri() . '/images/protected-' . $thumbnail . '.gif'; ?>">
<img src="<?php echo get_template_directory_uri() . '/images/placeholder-' . $thumbnail . '.gif'; ?>">
<img src="<?php echo get_template_directory_uri() . '/images/protected-' . $thumbnail . '.gif'; ?>">
<img src="<?php echo get_template_directory_uri() . '/images/placeholder-' . $thumbnail . '.gif'; ?>">
<img src="<?php echo get_template_directory_uri() . '/images/protected-' . $thumbnail . '.gif'; ?>">
<img src="<?php echo get_template_directory_uri() . '/images/placeholder-' . $thumbnail . '.gif'; ?>">
As well as the following
href
attributes:echo '<link rel="shortcut icon" href="'. $favicon .'"/>
<a href="' . admin_url() . '" title="' . __( 'Return to the Dashboard', 'tgmpa' ) . '">
<a href="' . add_query_arg( ... )
admin_url()
add_query_arg( ... )
add_query_arg( ... )
add_query_arg( ... )
add_query_arg( ... )
add_query_arg( ... )
add_query_arg( ... )
admin_url()
add_query_arg( ... )
add_query_arg( ... )
home_url()