| @@ -1,10 +1,19 @@ | ||
| 1 | 1 | <div |
| 2 | - <?php echo $wrapper_attr; //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>> | |
| 2 | + <?php | |
| 3 | +// phpcs:disable WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound -- view template receives variables via extract(); prefixing is impractical. | |
| 4 | +if ( ! defined( 'ABSPATH' ) ) { | |
| 5 | + exit; | |
| 6 | +} | |
| 7 | +echo $wrapper_attr; //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>> | |
| 3 | 8 | <div class="betterdocs-social-share-heading"> |
| 4 | 9 | <?php |
| 5 | 10 | if ( $title ) { |
| 6 | 11 | $title_tag = isset( $title_tag ) ? $title_tag : 'h4'; |
| 12 | + // Allow-list the tag name — esc_attr() does not stop a space/= from | |
| 13 | + // injecting an attribute in this tag-name position (stored XSS via | |
| 14 | + // the shortcode title_tag). | |
| 15 | + $title_tag = betterdocs()->template_helper->is_valid_tag( $title_tag ); | |
| 7 | 16 | echo wp_sprintf( '<%1$s class="betterdocs-social-share-title-tag">%2$s</%1$s>', esc_attr( $title_tag ), esc_html( $title ) ); |
| 8 | 17 | } |
| 9 | 18 | ?> |
| 10 | 19 | </div> |