Only run stripslashes() on strings in update_usermeta(). Props stm. fixes #3240
git-svn-id: https://develop.svn.wordpress.org/trunk@4396 602fd350-edb4-49c9-b593-d223f7449a82
This commit is contained in:
parent
2cc7fdd66b
commit
60848ed137
@ -115,7 +115,8 @@ function update_usermeta( $user_id, $meta_key, $meta_value ) {
|
||||
$meta_key = preg_replace('|[^a-z0-9_]|i', '', $meta_key);
|
||||
|
||||
// FIXME: usermeta data is assumed to be already escaped
|
||||
$meta_value = stripslashes($meta_value);
|
||||
if ( is_string($meta_value) )
|
||||
$meta_value = stripslashes($meta_value);
|
||||
$meta_value = maybe_serialize($meta_value);
|
||||
$meta_value = $wpdb->escape($meta_value);
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user