| @@ -90,9 +90,9 @@ | ||
| 90 | 90 | if (ArrayHelper::get($data, 'settings.validation_rules.required.value')) { |
| 91 | 91 | $ariaRequired = 'true'; |
| 92 | 92 | } |
| 93 | 93 | |
| 94 | - $ariaLabelledBy = 'label_' . ArrayHelper::get($data, 'attributes.id'); | |
| 94 | + $ariaLabelledBy = esc_attr('label_' . ArrayHelper::get($data, 'attributes.id')); | |
| 95 | 95 | |
| 96 | 96 | $elMarkup = '<select ' . $atts . ' aria-invalid="false" aria-required="' . $ariaRequired . '" aria-labelledby="' . $ariaLabelledBy .'"'.'>' . $options . '</select>'; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- $atts, $options are escaped before being passed in. |
| 97 | 97 | |
| 98 | 98 | $html = $this->buildElementMarkup($elMarkup, $data, $form); |