From 621674572163d202f86028ba21c6f81b695a9a14 Mon Sep 17 00:00:00 2001 From: Sainath Poojary Date: Fri, 19 Jun 2026 00:06:59 +0530 Subject: [PATCH] Administration: Improve output escaping in template.php --- src/wp-admin/includes/template.php | 28 ++++++++++++++-------------- 1 file changed, 14 insertions(+), 14 deletions(-) diff --git a/src/wp-admin/includes/template.php b/src/wp-admin/includes/template.php index a24aae32cc8dd..65ff5fc7f4d2c 100644 --- a/src/wp-admin/includes/template.php +++ b/src/wp-admin/includes/template.php @@ -591,8 +591,8 @@ function list_meta( $meta ) { - - + + @@ -606,8 +606,8 @@ function list_meta( $meta ) { - - + + @@ -1040,7 +1040,7 @@ function wp_import_upload_form( $action ) { ?> - +

@@ -1385,7 +1385,7 @@ function do_meta_boxes( $screen, $context, $data_object ) { __( 'Warning:' ) . ' '; } - echo $box['title']; + echo esc_html( $box['title'] ); echo "\n"; if ( 'dashboard_browser_nag' !== $box['id'] ) { @@ -1778,7 +1778,7 @@ function do_settings_sections( $page ) { if ( $section['title'] ) { $unique_id = wp_unique_id( 'wp-settings-section-' . $section['id'] . '-' ); - echo '

' . $section['title'] . "

\n"; + echo '

' . esc_html( $section['title'] ) . "

\n"; } if ( $section['callback'] ) { @@ -1828,9 +1828,9 @@ function do_settings_fields( $page, $section ) { echo ""; if ( ! empty( $field['args']['label_for'] ) ) { - echo ''; + echo ''; } else { - echo ''; + echo ''; } echo '
' . $field['title'] . '' . esc_html( $field['title'] ) . ''; @@ -2013,7 +2013,7 @@ function settings_errors( $setting = '', $sanitize = false, $hide_on_update = fa ); $output .= "
\n"; - $output .= "

{$details['message']}

"; + $output .= '

' . wp_kses_post( $details['message'] ) . '

'; $output .= "
\n"; } @@ -2137,7 +2137,7 @@ function iframe_header( $title = '', $deprecated = false ) { header( 'Content-Type: ' . get_option( 'html_type' ) . '; charset=' . get_option( 'blog_charset' ) ); _wp_admin_html_begin(); ?> -<?php bloginfo( 'name' ); ?> › <?php echo $title; ?> — <?php _e( 'WordPress' ); ?> +<?php bloginfo( 'name' ); ?> › <?php echo esc_html( $title ); ?> — <?php _e( 'WordPress' ); ?> {$state}{$suffix}"; + $post_states_html .= '' . esc_html( $state ) . esc_html( $suffix ) . ''; } } @@ -2431,7 +2431,7 @@ function _media_states( $post, $display = true ) { $suffix = ( $i < $state_count ) ? $separator : ''; - $media_states_string .= "{$state}{$suffix}"; + $media_states_string .= '' . esc_html( $state ) . esc_html( $suffix ) . ''; } }