Changeset 2493496
- Timestamp:
- 03/11/2021 05:41:01 PM (5 years ago)
- Location:
- freetobook-review-widget
- Files:
-
- 2 edited
-
tags/1.1/freetobook-review-widget.php (modified) (3 diffs)
-
trunk/freetobook-review-widget.php (modified) (2 diffs)
Legend:
- Unmodified
- Added
- Removed
-
freetobook-review-widget/tags/1.1/freetobook-review-widget.php
r2492173 r2493496 101 101 <tr> 102 102 <td style="width:130px">Review Widget Key</td> 103 <td><input type="text" size="20" name="ftb-review-widget-key" value="' . $this->widget_key. '" ></td>103 <td><input type="text" size="20" name="ftb-review-widget-key" value="' . esc_attr($this->widget_key) . '" ></td> 104 104 </tr> 105 105 … … 133 133 134 134 if (!empty($_POST['ftb-review-widget-key'])) { 135 $reviewWidgetKey = trim($_POST['ftb-review-widget-key']);135 $reviewWidgetKey = sanitize_text_field($_POST['ftb-review-widget-key']); 136 136 if (preg_match('/^[a-z0-9]+$/i', $reviewWidgetKey) === 1) { 137 137 check_admin_referer('freetobook_review_update', 'ftb_nonce'); … … 253 253 <br> 254 254 <div style="text-align:center;width:220px;margin:0 auto;"> 255 Width:<input readonly type="text" size="3" 255 Width:<input readonly type="text" size="3" 256 256 id="ftb_review_width_<?php echo $this->number?>" 257 257 name="<?php echo $this->get_field_name( 'width' ) ?>" -
freetobook-review-widget/trunk/freetobook-review-widget.php
r2492145 r2493496 101 101 <tr> 102 102 <td style="width:130px">Review Widget Key</td> 103 <td><input type="text" size="20" name="ftb-review-widget-key" value="' . $this->widget_key. '" ></td>103 <td><input type="text" size="20" name="ftb-review-widget-key" value="' . esc_attr($this->widget_key) . '" ></td> 104 104 </tr> 105 105 … … 133 133 134 134 if (!empty($_POST['ftb-review-widget-key'])) { 135 $reviewWidgetKey = trim($_POST['ftb-review-widget-key']);135 $reviewWidgetKey = sanitize_text_field($_POST['ftb-review-widget-key']); 136 136 if (preg_match('/^[a-z0-9]+$/i', $reviewWidgetKey) === 1) { 137 137 check_admin_referer('freetobook_review_update', 'ftb_nonce');
Note: See TracChangeset
for help on using the changeset viewer.