Skip to:
Content

bbPress.org


Ignore:
Timestamp:
07/17/2013 07:35:03 PM (13 years ago)
Author:
johnjamesjacoby
Message:

For all template functions that output URL's, always echo an escaped value using esc_url(). See #2367.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/includes/forums/template-tags.php

    r5002 r5037  
    231231 */
    232232function bbp_forum_permalink( $forum_id = 0 ) {
    233     echo bbp_get_forum_permalink( $forum_id );
     233    echo esc_url( bbp_get_forum_permalink( $forum_id ) );
    234234}
    235235    /**
     
    807807 */
    808808function bbp_forum_last_topic_permalink( $forum_id = 0 ) {
    809     echo bbp_get_forum_last_topic_permalink( $forum_id );
     809    echo esc_url( bbp_get_forum_last_topic_permalink( $forum_id ) );
    810810}
    811811    /**
     
    949949 */
    950950function bbp_forum_last_reply_permalink( $forum_id = 0 ) {
    951     echo bbp_get_forum_last_reply_permalink( $forum_id );
     951    echo esc_url( bbp_get_forum_last_reply_permalink( $forum_id ) );
    952952}
    953953    /**
     
    978978 */
    979979function bbp_forum_last_reply_url( $forum_id = 0 ) {
    980     echo bbp_get_forum_last_reply_url( $forum_id );
     980    echo esc_url( bbp_get_forum_last_reply_url( $forum_id ) );
    981981}
    982982    /**
Note: See TracChangeset for help on using the changeset viewer.