PluginProbe
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder / 6.2.15
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder v6.2.15
6.2.15 6.2.14 6.2.13 6.2.12 6.2.10 6.2.11 6.2.9 6.2.8 6.2.7 6.2.6 6.2.5 6.2.4 6.2.3 6.2.2 3.6.22 3.6.31 3.6.40 3.6.41 3.6.42 3.6.50 3.6.51 3.6.60 3.6.61 3.6.62 3.6.64 All 197 releases
← All changes | app/Services/FormBuilder/Components/TabularGrid.php +2 -1 6.2.13 → 6.2.15 View file →
@@ -67,9 +67,10 @@
67 67
68 68 // SECURITY (FINDING-12): esc_attr the row/column labels before interpolating them
69 69 // into the double-quoted aria-label; save-time sanitizers do not encode quotes.
70 70 $input = '<input aria-label="'. esc_attr($row['name']) .'-'. esc_attr($column['label']) . '" ' . $attributes . " {$isChecked} aria-invalid='false' aria-required={$ariaRequired}>"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- $attributes is escaped before being passed in.
71 - $elMarkup .= "<td data-label='" . fluentform_sanitize_html($column['label']) . "'>{$input}</td>";
71 + $responsiveLabel = esc_attr(wp_strip_all_tags($column['label']));
72 + $elMarkup .= "<td data-label='{$responsiveLabel}'>{$input}</td>";
72 73 }
73 74 $elMarkup .= '</tr>';
74 75 }
75 76