PluginProbe
BetterDocs – AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ & Chatbot / 4.9.2
BetterDocs – AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ & Chatbot v4.9.2
4.9.2 4.9.1 4.9.0 4.8.2 4.8.1 4.8.0 4.7.0 4.6.2 4.6.1 4.6.0 4.5.6 4.5.5 4.5.4 4.5.3 4.5.2 4.5.1 4.5.0 4.4.1 4.4.0 3.3.4 3.4.0 3.4.1 3.4.2 3.5.0 3.5.1 All 200 releases
← All changes | views/widgets/social.php +10 -1 4.4.04.9.2 View file →
@@ -1,10 +1,19 @@
1 1 <div
2 - <?php echo $wrapper_attr; //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>>
2 + <?php
3 +// phpcs:disable WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound -- view template receives variables via extract(); prefixing is impractical.
4 +if ( ! defined( 'ABSPATH' ) ) {
5 + exit;
6 +}
7 +echo $wrapper_attr; //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>>
3 8 <div class="betterdocs-social-share-heading">
4 9 <?php
5 10 if ( $title ) {
6 11 $title_tag = isset( $title_tag ) ? $title_tag : 'h4';
12 + // Allow-list the tag name — esc_attr() does not stop a space/= from
13 + // injecting an attribute in this tag-name position (stored XSS via
14 + // the shortcode title_tag).
15 + $title_tag = betterdocs()->template_helper->is_valid_tag( $title_tag );
7 16 echo wp_sprintf( '<%1$s class="betterdocs-social-share-title-tag">%2$s</%1$s>', esc_attr( $title_tag ), esc_html( $title ) );
8 17 }
9 18 ?>
10 19 </div>