| @@ -10,19 +10,23 @@ | ||
| 10 | 10 | if ( ! defined( 'ABSPATH' ) ) exit; // Exit if accessed directly |
| 11 | 11 | |
| 12 | 12 | global $post, $property; |
| 13 | 13 | |
| 14 | +// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound -- Template-local variable; the template is included through a helper/function scope, so PrefixAllGlobals misclassifies the file when checked standalone. | |
| 14 | 15 | $description = $property->get_formatted_description(); |
| 15 | 16 | |
| 16 | -if ( trim(strip_tags($description)) != '' ) | |
| 17 | +if ( trim(wp_strip_all_tags($description)) != '' ) | |
| 17 | 18 | { |
| 18 | 19 | ?> |
| 19 | 20 | <div class="description"> |
| 20 | 21 | |
| 21 | - <h4><?php _e( 'Full Details', 'propertyhive' ); ?></h4> | |
| 22 | + <h4><?php echo esc_html(__( 'Full Details', 'propertyhive' )); ?></h4> | |
| 22 | 23 | |
| 23 | - <?php echo $description; ?> | |
| 24 | + <div class="description-contents"><?php | |
| 25 | + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Stored description fields are sanitized before the trusted propertyhive_get_detail and propertyhive_description_output HTML extension hooks; preserve their embed output. | |
| 26 | + echo $description; | |
| 27 | + ?></div> | |
| 24 | 28 | |
| 25 | 29 | </div> |
| 26 | 30 | <?php |
| 27 | 31 | } |
| 28 | 32 | ?> |