PluginProbe
BetterDocs – AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ & Chatbot / 4.9.3
BetterDocs – AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ & Chatbot v4.9.3
4.9.3 4.9.2 4.9.1 4.9.0 4.8.2 4.8.1 4.8.0 4.7.0 4.6.2 4.6.1 4.6.0 4.5.6 4.5.5 4.5.4 4.5.3 4.5.2 4.5.1 4.5.0 4.4.1 4.4.0 3.3.4 3.4.0 3.4.1 3.4.2 3.5.0 All 201 releases
← All changes | views/widgets/reactions.php +4 -0 4.7.0 → 4.9.3 View file →
@@ -7,8 +7,12 @@
7 7 echo $wrapper_attr; //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>>
8 8 <?php
9 9 if ( $reactions_text ) {
10 10 $text_tag = isset( $text_tag ) ? $text_tag : 'h5';
11 + // The tag lands in a tag-name position where esc_attr() does NOT stop a
12 + // space/= from injecting an attribute (stored XSS via the shortcode
13 + // text_tag). Clamp it to a safe HTML tag via the allow-list.
14 + $text_tag = betterdocs()->template_helper->is_valid_tag( $text_tag );
11 15 echo wp_sprintf( '<div class="betterdocs-article-reactions-heading"><%1$s class="betterdocs-reactions-title-tag">%2$s</%1$s></div>', esc_attr( $text_tag ), esc_html( $reactions_text ) );
12 16 }
13 17 ?>
14 18 <ul class="betterdocs-article-reaction-links layout-1">