Plugin Directory

Changeset 3219730


Ignore:
Timestamp:
01/09/2025 03:42:11 PM (14 months ago)
Author:
tinuzz
Message:

Release v5.0.3

Location:
trackserver/trunk
Files:
3 edited

Legend:

Unmodified
Added
Removed
  • trackserver/trunk/class-trackserver-shortcode.php

    r2860786 r3219730  
    107107        $class_str = '';
    108108        if ( count( $classes ) ) {
    109             $class_str = 'class="' . implode( ' ', $classes ) . '"';
     109            $class_str = 'class="' . esc_attr( implode( ' ', $classes ) ) . '"';
    110110        }
    111111
     
    329329        $class_str = '';
    330330        if ( $atts['class'] ) {
    331             $class_str = 'class="' . htmlspecialchars( $atts['class'] ) . '"';
     331            $class_str = 'class="' . esc_attr( $atts['class'] ) . '"';
    332332        }
    333333
  • trackserver/trunk/readme.txt

    r3151401 r3219730  
    44Tags: gps, gpx, map, leaflet, track, mobile, tracking
    55Requires at least: 4.7
    6 Tested up to: 6.6
     6Tested up to: 6.7
    77Stable tag: trunk
    88License: GPLv2 or later
     
    266266
    267267== Changelog ==
     268
     269= v5.0.3 =
     270Release date: 09 January 2025
     271
     272Fixed:
     273* XSS in the 'tsmap' shortcode handler (CVE-2024-12505).
    268274
    269275= v5.0.2 =
  • trackserver/trunk/trackserver.php

    r2874962 r3219730  
    66Plugin URI: https://www.grendelman.net/wp/trackserver-wordpress-plugin/
    77Description: GPS Track Server for TrackMe, OruxMaps and others
    8 Version: 5.0.2
     8Version: 5.0.3
    99Author: Martijn Grendelman
    1010Author URI: http://www.grendelman.net/
     
    1414
    1515=== RELEASE HISTORY ===
     162025-01-09 - v5.0.3 - fix XSS in shortcode, reported by yudha @ Wordfence
    16172023-03-05 - v5.0.2 - Bugfix
    17182023-02-06 - v5.0  - new features, code refactoring, leaflet 1.9.3
Note: See TracChangeset for help on using the changeset viewer.