| @@ -19,8 +19,12 @@ | ||
| 19 | 19 | * |
| 20 | 20 | * @package automattic/jetpack |
| 21 | 21 | */ |
| 22 | 22 | |
| 23 | +if ( ! defined( 'ABSPATH' ) ) { | |
| 24 | + exit( 0 ); | |
| 25 | +} | |
| 26 | + | |
| 23 | 27 | /** |
| 24 | 28 | * SoundCloud shortcode handler |
| 25 | 29 | * |
| 26 | 30 | * @param string|array $atts The attributes passed to the shortcode like [soundcloud attr1="value" /]. |
| @@ -165,9 +169,9 @@ | ||
| 165 | 169 | return sprintf( |
| 166 | 170 | '<iframe width="%1$s" height="%2$d" scrolling="no" frameborder="no" src="%3$s"></iframe>', |
| 167 | 171 | esc_attr( $width ), |
| 168 | 172 | esc_attr( $height ), |
| 169 | - $url | |
| 173 | + esc_url( $url ) | |
| 170 | 174 | ); |
| 171 | 175 | } |
| 172 | 176 | add_shortcode( 'soundcloud', 'soundcloud_shortcode' ); |
| 173 | 177 | |
| @@ -260,5 +264,8 @@ | ||
| 260 | 264 | } |
| 261 | 265 | |
| 262 | 266 | return $content; |
| 263 | 267 | } |
| 264 | -add_filter( 'pre_kses', 'jetpack_soundcloud_embed_reversal' ); | |
| 268 | + | |
| 269 | +if ( jetpack_shortcodes_should_hook_pre_kses() ) { | |
| 270 | + add_filter( 'pre_kses', 'jetpack_soundcloud_embed_reversal' ); | |
| 271 | +} | |