| @@ -1,20 +1,10 @@ | ||
| 1 | 1 | <div |
| 2 | - <?php | |
| 3 | -// phpcs:disable WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound -- view template receives variables via extract(); prefixing is impractical. | |
| 4 | -if ( ! defined( 'ABSPATH' ) ) { | |
| 5 | - exit; | |
| 6 | -} | |
| 7 | -echo $wrapper_attr; //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>> | |
| 2 | + <?php echo $wrapper_attr; //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>> | |
| 8 | 3 | <div class="betterdocs-social-share-heading"> |
| 9 | 4 | <?php |
| 10 | 5 | if ( $title ) { |
| 11 | - $title_tag = isset( $title_tag ) ? $title_tag : 'h4'; | |
| 12 | - // Allow-list the tag name — esc_attr() does not stop a space/= from | |
| 13 | - // injecting an attribute in this tag-name position (stored XSS via | |
| 14 | - // the shortcode title_tag). | |
| 15 | - $title_tag = betterdocs()->template_helper->is_valid_tag( $title_tag ); | |
| 16 | - echo wp_sprintf( '<%1$s class="betterdocs-social-share-title-tag">%2$s</%1$s>', esc_attr( $title_tag ), esc_html( $title ) ); | |
| 6 | + echo wp_sprintf( '<h5>%s</h5>', esc_html( $title ) ); | |
| 17 | 7 | } |
| 18 | 8 | ?> |
| 19 | 9 | </div> |
| 20 | 10 | |