| @@ -5,9 +5,9 @@ | ||
| 5 | 5 | |
| 6 | 6 | if ( isset( $message ) && '' !== $message ) { |
| 7 | 7 | if ( FrmAppHelper::is_admin() ) { |
| 8 | 8 | echo '<div class="frm_updated_message">'; |
| 9 | - FrmAppHelper::kses_echo( $message, 'all' ); | |
| 9 | + echo FrmAppHelper::kses( $message, 'all' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped | |
| 10 | 10 | echo '</div>'; |
| 11 | 11 | } else { |
| 12 | 12 | echo FrmAppHelper::maybe_kses( $message ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped |
| 13 | 13 | } |
| @@ -15,11 +15,9 @@ | ||
| 15 | 15 | |
| 16 | 16 | if ( ! isset( $show_messages ) ) { |
| 17 | 17 | $show_messages = array(); |
| 18 | 18 | } |
| 19 | - | |
| 20 | 19 | $show_messages = apply_filters( 'frm_message_list', $show_messages ); |
| 21 | - | |
| 22 | 20 | if ( is_array( $show_messages ) && count( $show_messages ) > 0 ) { |
| 23 | 21 | // Define a callback function to add 'data-action' attribute to allowed HTML tags |
| 24 | 22 | $add_data_action_callback = function ( $allowed_html ) { |
| 25 | 23 | $allowed_html['span']['data-action'] = true; |
| @@ -30,9 +28,8 @@ | ||
| 30 | 28 | <ul id="frm_messages"> |
| 31 | 29 | <?php |
| 32 | 30 | // Add the callback function to the 'frm_striphtml_allowed_tags' filter |
| 33 | 31 | add_filter( 'frm_striphtml_allowed_tags', $add_data_action_callback ); |
| 34 | - | |
| 35 | 32 | foreach ( $show_messages as $m ) { |
| 36 | 33 | echo '<li>' . FrmAppHelper::kses( $m, array( 'a', 'br', 'span', 'p', 'svg', 'use' ) ) . '</li>'; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped |
| 37 | 34 | } |
| 38 | 35 | // Remove the callback function from the 'frm_striphtml_allowed_tags' filter |