PluginProbe
BetterDocs – AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ & Chatbot / 4.9.3
BetterDocs – AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ & Chatbot v4.9.3
4.9.3 4.9.2 4.9.1 4.9.0 4.8.2 4.8.1 4.8.0 4.7.0 4.6.2 4.6.1 4.6.0 4.5.6 4.5.5 4.5.4 4.5.3 4.5.2 4.5.1 4.5.0 4.4.1 4.4.0 3.3.4 3.4.0 3.4.1 3.4.2 3.5.0 All 201 releases
← All changes | views/widgets/reactions-3.php +3 -0 4.5.6 → 4.9.3 View file →
@@ -7,8 +7,11 @@
7 7 echo $wrapper_attr; //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>>
8 8 <div class="betterdocs-article-reactions-sidebar">
9 9 <?php
10 10 $text_tag = isset( $text_tag ) ? $text_tag : 'h5';
11 + // Allow-list the tag name — esc_attr() does not stop a space/= from
12 + // injecting an attribute in this tag-name position (stored XSS).
13 + $text_tag = betterdocs()->template_helper->is_valid_tag( $text_tag );
11 14 echo wp_sprintf( '<%1$s class="betterdocs-reactions-title-tag">%2$s</%1$s>', esc_attr( $text_tag ), esc_html( $reactions_text ) );
12 15 ?>
13 16 <ul class="betterdocs-article-reaction-links layout-3">
14 17 <?php if ( isset( $happy ) && $happy == true ) { ?>