| @@ -7,8 +7,12 @@ | ||
| 7 | 7 | echo $wrapper_attr; //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>> |
| 8 | 8 | <?php |
| 9 | 9 | if ( $reactions_text ) { |
| 10 | 10 | $text_tag = isset( $text_tag ) ? $text_tag : 'h5'; |
| 11 | + // The tag lands in a tag-name position where esc_attr() does NOT stop a | |
| 12 | + // space/= from injecting an attribute (stored XSS via the shortcode | |
| 13 | + // text_tag). Clamp it to a safe HTML tag via the allow-list. | |
| 14 | + $text_tag = betterdocs()->template_helper->is_valid_tag( $text_tag ); | |
| 11 | 15 | echo wp_sprintf( '<div class="betterdocs-article-reactions-heading"><%1$s class="betterdocs-reactions-title-tag">%2$s</%1$s></div>', esc_attr( $text_tag ), esc_html( $reactions_text ) ); |
| 12 | 16 | } |
| 13 | 17 | ?> |
| 14 | 18 | <ul class="betterdocs-article-reaction-links layout-1"> |