PluginProbe
GiveWP – Donation Plugin and Fundraising Platform / 4.16.9
GiveWP – Donation Plugin and Fundraising Platform v4.16.9
4.16.9 4.16.8.1 4.16.8 4.16.7.2 4.16.7.1 4.16.7 4.16.6.1 4.16.6 4.16.5.1 4.16.5 4.16.4 4.16.3 4.16.2 4.16.1 4.16.0 4.15.5 4.15.4 4.15.3 4.15.2 4.15.1 4.15.0 2.3.0 2.3.1 2.3.2 2.30.0 All 255 releases
← All changes | src/Campaigns/Blocks/CampaignComments/Controller/BlockRenderController.php +7 -5 4.15.44.16.9 View file →
@@ -9,8 +9,9 @@
9 9 */
10 10 class BlockRenderController
11 11 {
12 12 /**
13 + * @since 4.16.1 escape attribute values in block markup
13 14 * @since 4.0.0
14 15 */
15 16 public function render(array $attributes, string $secondaryColor): string
16 17 {
@@ -15,11 +16,12 @@
15 16 public function render(array $attributes, string $secondaryColor): string
16 17 {
17 18 $blockAttributes = BlockAttributes::fromArray($attributes);
18 19
19 - $encodedAttributes = json_encode($blockAttributes->toArray());
20 -
21 - $blockId = $blockAttributes->blockId;
22 -
23 - return "<div id='givewp-campaign-comments-block-{$blockId}' data-secondary-color='{$secondaryColor}' data-givewp-campaign-comments data-attributes='{$encodedAttributes}'></div>";
20 + return sprintf(
21 + "<div id='givewp-campaign-comments-block-%s' data-secondary-color='%s' data-givewp-campaign-comments data-attributes='%s'></div>",
22 + esc_attr((string) $blockAttributes->blockId),
23 + esc_attr($secondaryColor),
24 + esc_attr((string) json_encode($blockAttributes->toArray()))
25 + );
24 26 }
25 27 }