PluginProbe
BetterDocs – AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ & Chatbot / 4.9.2
BetterDocs – AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ & Chatbot v4.9.2
4.9.2 4.9.1 4.9.0 4.8.2 4.8.1 4.8.0 4.7.0 4.6.2 4.6.1 4.6.0 4.5.6 4.5.5 4.5.4 4.5.3 4.5.2 4.5.1 4.5.0 4.4.1 4.4.0 3.3.4 3.4.0 3.4.1 3.4.2 3.5.0 3.5.1 All 200 releases
← All changes | views/widgets/title.php +8 -1 3.4.24.9.2 View file →
@@ -1,4 +1,11 @@
1 1 <?php
2 2
3 +
4 +if ( ! defined( 'ABSPATH' ) ) {
5 + exit;
6 +}
3 7 $tag = empty( $tag ) ? 'h2' : $tag;
4 -echo sprintf( '<%1$s id="betterdocs-entry-title" class="betterdocs-entry-title" %2$s>%3$s</%1$s>', strtolower( $tag ), $wrapper_attr, wp_kses_post( $title ) );
8 +// $tag lands in a tag-name position, so clamp it to a safe HTML tag via the
9 +// allow-list rather than relying on strtolower() (which leaves a space/= intact).
10 +$tag = betterdocs()->template_helper->is_valid_tag( $tag );
11 +printf( '<%1$s id="betterdocs-entry-title" class="betterdocs-entry-title" %2$s>%3$s</%1$s>', $tag, $wrapper_attr, wp_kses_post( $title ) ); //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped