← All changes
|
src/Views/Form/Templates/Sequoia/sections/introduction.php
+7
-3
4.16.1
→
4.17.0
View file →
| @@ -1,6 +1,11 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | |
| 3 | +/** | |
| 4 | + * @since 4.16.4 Escaped the introduction headline output. | |
| 5 | + * @since 4.16.2 Escape introduction image URL when rendering the template. | |
| 6 | + */ | |
| 7 | + | |
| 3 | 8 | use Give\Helpers\Form\Template\Utils\Frontend as FrontendFormTemplateUtils; |
| 4 | 9 | |
| 5 | 10 | $formInfo = get_post(FrontendFormTemplateUtils::getFormId()); |
| 6 | 11 | |
| @@ -15,9 +20,9 @@ | ||
| 15 | 20 | |
| 16 | 21 | <div class="give-section introduction"> |
| 17 | 22 | <h2 class="headline"> |
| 18 | 23 | <?php |
| 19 | - echo $headline; ?> | |
| 24 | + echo esc_html($headline); ?> | |
| 20 | 25 | </h2> |
| 21 | 26 | <?php |
| 22 | 27 | if ( ! empty($description)) : ?> |
| 23 | 28 | <div class="seperator"></div> |
| @@ -29,10 +34,9 @@ | ||
| 29 | 34 | endif; ?> |
| 30 | 35 | <?php |
| 31 | 36 | if ( ! empty($image)) : ?> |
| 32 | 37 | <div class="image"> |
| 33 | - <img src="<?php | |
| 34 | - echo $image; ?>" /> | |
| 38 | + <img src="<?php echo esc_url( $image ); ?>" /> | |
| 35 | 39 | </div> |
| 36 | 40 | <?php |
| 37 | 41 | endif; ?> |
| 38 | 42 | |