Privacy: Pass admin URLs for data export and erase forms through esc_url().

Introduced in [45149].

Props: birgire.
Fixes #44047.

git-svn-id: https://develop.svn.wordpress.org/trunk@45154 602fd350-edb4-49c9-b593-d223f7449a82
This commit is contained in:
Jonathan Desrosiers 2019-04-09 14:06:29 +00:00
parent 632ad28223
commit 7215374431

View File

@ -830,7 +830,7 @@ function _wp_personal_data_export_page() {
<?php settings_errors(); ?>
<form action="<?php echo admin_url( 'tools.php?page=export_personal_data' ); ?>" method="post" class="wp-privacy-request-form">
<form action="<?php echo esc_url( admin_url( 'tools.php?page=export_personal_data' ) ); ?>" method="post" class="wp-privacy-request-form">
<h2><?php esc_html_e( 'Add Data Export Request' ); ?></h2>
<p><?php esc_html_e( 'An email will be sent to the user at this email address asking them to verify the request.' ); ?></p>
@ -914,7 +914,7 @@ function _wp_personal_data_removal_page() {
<?php settings_errors(); ?>
<form action="<?php echo admin_url( 'tools.php?page=remove_personal_data' ); ?>" method="post" class="wp-privacy-request-form">
<form action="<?php echo esc_url( admin_url( 'tools.php?page=remove_personal_data' ) ); ?>" method="post" class="wp-privacy-request-form">
<h2><?php esc_html_e( 'Add Data Erasure Request' ); ?></h2>
<p><?php esc_html_e( 'An email will be sent to the user at this email address asking them to verify the request.' ); ?></p>