PluginProbe
Gutenberg / trunk
Gutenberg vtrunk
24.1.0 24.0.0 23.9.1 23.9.0 23.8.0 23.7.2 23.7.1 23.7.0 23.6.1 23.6.2 23.6.0 23.5.3 23.5.2 23.5.1 23.5.0 23.4.0 23.3.2 23.3.1 23.3.0 23.2.0 23.2.1 23.2.2 23.1.1 23.1.0 23.0.1 All 404 releases
← All changes | build/scripts/block-library/image.php +10 -4 23.6.2 → trunk View file →
@@ -289,14 +289,14 @@
289 289
290 290 $body_content = $processor->get_updated_html();
291 291
292 292 // Adds a button alongside image in the body content.
293 + // Extract the img tag using preg_match for structured access.
293 294 $img = null;
294 295 preg_match( '/<img[^>]+>/', $body_content, $img );
295 296
296 - $button =
297 - $img[0]
298 - . '<button
297 + if ( isset( $img[0] ) ) {
298 + $button_html = '<button
299 299 class="lightbox-trigger"
300 300 type="button"
301 301 aria-haspopup="dialog"
302 302 data-wp-bind--aria-label="state.thisImage.triggerButtonAriaLabel"
@@ -309,9 +309,15 @@
309 309 <path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z" />
310 310 </svg>
311 311 </button>';
312 312
313 - $body_content = preg_replace( '/<img[^>]+>/', $button, $body_content );
313 + // Build the replacement: img tag + button.
314 + // Use str_replace for literal replacement instead of preg_replace to avoid
315 + // PCRE backreference interpretation of $ and \ sequences in user-controlled
316 + // image attributes (e.g., alt="Just $5 today").
317 + $button = $img[0] . $button_html;
318 + $body_content = str_replace( $img[0], $button, $body_content );
319 + }
314 320
315 321 add_action( 'wp_footer', 'gutenberg_block_core_image_print_lightbox_overlay' );
316 322
317 323 return $body_content;