diff --git a/wp-includes/kses.php b/wp-includes/kses.php index 79f5366fe5..8dc776a945 100644 --- a/wp-includes/kses.php +++ b/wp-includes/kses.php @@ -431,6 +431,10 @@ function wp_kses_split2($string, $allowed_html, $allowed_protocols) { $string = $newstring; if ( $string == '' ) return ''; + // prevent multiple dashes in comments + $string = preg_replace('/--+/', '-', $string); + // prevent three dashes closing a comment + $string = preg_replace('/-$/', '', $string); return ""; } # Allow HTML comments @@ -1052,4 +1056,4 @@ function kses_init() { add_action('init', 'kses_init'); add_action('set_current_user', 'kses_init'); -?> \ No newline at end of file +?>