| @@ -1,9 +1,17 @@ | ||
| 1 | 1 | <div |
| 2 | - <?php echo $wrapper_attr; //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>> | |
| 2 | + <?php | |
| 3 | +// phpcs:disable WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound -- view template receives variables via extract(); prefixing is impractical. | |
| 4 | +if ( ! defined( 'ABSPATH' ) ) { | |
| 5 | + exit; | |
| 6 | +} | |
| 7 | +echo $wrapper_attr; //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>> | |
| 3 | 8 | <div class="betterdocs-article-reactions-sidebar"> |
| 4 | 9 | <?php |
| 5 | 10 | $text_tag = isset( $text_tag ) ? $text_tag : 'h5'; |
| 11 | + // Allow-list the tag name — esc_attr() does not stop a space/= from | |
| 12 | + // injecting an attribute in this tag-name position (stored XSS). | |
| 13 | + $text_tag = betterdocs()->template_helper->is_valid_tag( $text_tag ); | |
| 6 | 14 | echo wp_sprintf( '<%1$s class="betterdocs-reactions-title-tag">%2$s</%1$s>', esc_attr( $text_tag ), esc_html( $reactions_text ) ); |
| 7 | 15 | ?> |
| 8 | 16 | <ul class="betterdocs-article-reaction-links layout-3"> |
| 9 | 17 | <?php if ( isset( $happy ) && $happy == true ) { ?> |