PluginProbe
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder / trunk
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder vtrunk
6.2.15 6.2.14 6.2.13 6.2.12 6.2.10 6.2.11 6.2.9 6.2.8 6.2.7 6.2.6 6.2.5 6.2.4 6.2.3 6.2.2 3.6.22 3.6.31 3.6.40 3.6.41 3.6.42 3.6.50 3.6.51 3.6.60 3.6.61 3.6.62 3.6.64 All 197 releases
← All changes | app/Services/FormBuilder/Components/TabularGrid.php +2 -1 6.2.13 → trunk View file →
@@ -67,9 +67,10 @@
67 67
68 68 // SECURITY (FINDING-12): esc_attr the row/column labels before interpolating them
69 69 // into the double-quoted aria-label; save-time sanitizers do not encode quotes.
70 70 $input = '<input aria-label="'. esc_attr($row['name']) .'-'. esc_attr($column['label']) . '" ' . $attributes . " {$isChecked} aria-invalid='false' aria-required={$ariaRequired}>"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- $attributes is escaped before being passed in.
71 - $elMarkup .= "<td data-label='" . fluentform_sanitize_html($column['label']) . "'>{$input}</td>";
71 + $responsiveLabel = esc_attr(wp_strip_all_tags($column['label']));
72 + $elMarkup .= "<td data-label='{$responsiveLabel}'>{$input}</td>";
72 73 }
73 74 $elMarkup .= '</tr>';
74 75 }
75 76