| @@ -55,10 +55,20 @@ | ||
| 55 | 55 | } |
| 56 | 56 | |
| 57 | 57 | $tag_name = 'div'; |
| 58 | 58 | |
| 59 | - if ( ! empty( $attributes['tagName'] ) && tag_escape( $attributes['tagName'] ) === $attributes['tagName'] ) { | |
| 60 | - $tag_name = $attributes['tagName']; | |
| 59 | + if ( isset( $attributes['tagName'] ) && is_string( $attributes['tagName'] ) ) { | |
| 60 | + /** | |
| 61 | + * The allowed tag names match the options offered in the editor. | |
| 62 | + * | |
| 63 | + * @see packages/block-library/src/post-content/edit.jsx | |
| 64 | + */ | |
| 65 | + $allowed_tag_names = array( 'div', 'main', 'section', 'article' ); | |
| 66 | + $normalized_tag_name = strtolower( $attributes['tagName'] ); | |
| 67 | + | |
| 68 | + if ( in_array( $normalized_tag_name, $allowed_tag_names, true ) ) { | |
| 69 | + $tag_name = $normalized_tag_name; | |
| 70 | + } | |
| 61 | 71 | } |
| 62 | 72 | |
| 63 | 73 | $wrapper_attributes = get_block_wrapper_attributes( array( 'class' => 'entry-content' ) ); |
| 64 | 74 | |