Skip to:
Content

bbPress.org


Ignore:
Timestamp:
01/22/2013 06:51:56 PM (13 years ago)
Author:
johnjamesjacoby
Message:

Prepare $username in bbp_user_maybe_convert_pass(). Props Maty.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/includes/users/functions.php

    r4677 r4706  
    11251125
    11261126    // Bail if no user password to convert
    1127     $row = $wpdb->get_row( "SELECT * FROM {$wpdb->users} INNER JOIN {$wpdb->usermeta} ON user_id = ID WHERE meta_key = '_bbp_class' AND user_login = '{$username}' LIMIT 1" );
     1127    $row = $wpdb->get_row( $wpdb->prepare( "SELECT * FROM {$wpdb->users} INNER JOIN {$wpdb->usermeta} ON user_id = ID WHERE meta_key = '_bbp_class' AND user_login = '%s' LIMIT 1", $username ) );
    11281128    if ( empty( $row ) || is_wp_error( $row ) )
    11291129        return;
Note: See TracChangeset for help on using the changeset viewer.