From 52ae9779923aef4d36f4b4138ce943e304008edd Mon Sep 17 00:00:00 2001 From: Ryan Boren Date: Wed, 28 Jul 2004 23:09:33 +0000 Subject: [PATCH] Run htmlspecialchars on title attribute text in get_archives_link(). Bug 0000162. git-svn-id: https://develop.svn.wordpress.org/trunk@1497 602fd350-edb4-49c9-b593-d223f7449a82 --- wp-includes/template-functions-general.php | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/wp-includes/template-functions-general.php b/wp-includes/template-functions-general.php index 3b4394a403..06394165b7 100644 --- a/wp-includes/template-functions-general.php +++ b/wp-includes/template-functions-general.php @@ -194,14 +194,16 @@ function single_month_title($prefix = '', $display = true ) { /* link navigation hack by Orien http://icecode.com/ */ function get_archives_link($url, $text, $format = 'html', $before = '', $after = '') { $text = wptexturize($text); + $title_text = htmlspecialchars($text); + if ('link' == $format) { - return "\t\n"; + return "\t\n"; } elseif ('option' == $format) { return "\t\n"; } elseif ('html' == $format) { - return "\t
  • $before$text$after
  • \n"; + return "\t
  • $before$text$after
  • \n"; } else { // custom - return "\t$before$text$after\n"; + return "\t$before$text$after\n"; } }