PluginProbe
Gutenberg / 24.1.0
Gutenberg v24.1.0
24.1.0 24.0.0 23.9.1 23.9.0 23.8.0 23.7.2 23.7.1 23.7.0 23.6.1 23.6.2 23.6.0 23.5.3 23.5.2 23.5.1 23.5.0 23.4.0 23.3.2 23.3.1 23.3.0 23.2.0 23.2.1 23.2.2 23.1.1 23.1.0 23.0.1 All 404 releases
← All changes | build/scripts/block-library/image.php +10 -4 23.7.0 → 24.1.0 View file →
@@ -289,14 +289,14 @@
289 289
290 290 $body_content = $processor->get_updated_html();
291 291
292 292 // Adds a button alongside image in the body content.
293 + // Extract the img tag using preg_match for structured access.
293 294 $img = null;
294 295 preg_match( '/<img[^>]+>/', $body_content, $img );
295 296
296 - $button =
297 - $img[0]
298 - . '<button
297 + if ( isset( $img[0] ) ) {
298 + $button_html = '<button
299 299 class="lightbox-trigger"
300 300 type="button"
301 301 aria-haspopup="dialog"
302 302 data-wp-bind--aria-label="state.thisImage.triggerButtonAriaLabel"
@@ -309,9 +309,15 @@
309 309 <path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z" />
310 310 </svg>
311 311 </button>';
312 312
313 - $body_content = preg_replace( '/<img[^>]+>/', $button, $body_content );
313 + // Build the replacement: img tag + button.
314 + // Use str_replace for literal replacement instead of preg_replace to avoid
315 + // PCRE backreference interpretation of $ and \ sequences in user-controlled
316 + // image attributes (e.g., alt="Just $5 today").
317 + $button = $img[0] . $button_html;
318 + $body_content = str_replace( $img[0], $button, $body_content );
319 + }
314 320
315 321 add_action( 'wp_footer', 'gutenberg_block_core_image_print_lightbox_overlay' );
316 322
317 323 return $body_content;