From 6e9a0fb9487356e320d3d7c877f650646dbef44f Mon Sep 17 00:00:00 2001 From: Nikolay Bachiyski Date: Tue, 21 Jun 2016 14:18:27 +0000 Subject: [PATCH] Admin: Escape attachment name in case it contains special characters git-svn-id: https://develop.svn.wordpress.org/trunk@37774 602fd350-edb4-49c9-b593-d223f7449a82 --- src/wp-admin/includes/class-wp-media-list-table.php | 2 +- src/wp-includes/post-template.php | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/src/wp-admin/includes/class-wp-media-list-table.php b/src/wp-admin/includes/class-wp-media-list-table.php index 3a61f159bc..d7b17c5685 100644 --- a/src/wp-admin/includes/class-wp-media-list-table.php +++ b/src/wp-admin/includes/class-wp-media-list-table.php @@ -395,7 +395,7 @@ class WP_Media_List_Table extends WP_List_Table { ID ); - echo wp_basename( $file ); + echo esc_html( wp_basename( $file ) ); ?>

$link_text", $id, $size, $permalink, $icon, $text ); + return apply_filters( 'wp_get_attachment_link', "$link_text", $id, $size, $permalink, $icon, $text ); } /**