PluginProbe
Property Hive / 2.3.1
Property Hive v2.3.1
2.3.1 2.3.0 2.2.6 2.2.5 2.2.4 2.2.3 2.2.2 1.4.46 1.4.47 1.4.48 1.4.49 1.4.5 1.4.50 1.4.51 1.4.52 1.4.53 1.4.54 1.4.55 1.4.56 1.4.57 1.4.58 1.4.59 1.4.6 1.4.60 1.4.61 All 261 releases
← All changes | includes/bricks-builder-widgets/property-type.php +5 -3 2.2.22.3.1 View file →
@@ -70,12 +70,14 @@
70 70
71 71 // Add 'class' attribute to element root tag
72 72 $this->set_attribute( '_root', 'class', $root_classes );
73 73
74 + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Bricks serializes registered attributes through its documented render_attributes() API.
74 75 echo "<div {$this->render_attributes( '_root' )}>";
75 76
76 77 if ( isset( $this->settings['icon'] ) )
77 78 {
79 + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Bricks Element::render_icon() returns the icon-control HTML fragment, including i/svg markup; Bricks sanitizes uploaded SVGs at its documented upload boundary.
78 80 echo self::render_icon( $this->settings['icon'] );
79 81 echo ' ';
80 82 }
81 83
@@ -80,9 +82,9 @@
80 82 }
81 83
82 84 if ( isset($this->settings['before']) && !empty($this->settings['before']) )
83 85 {
84 - echo $this->settings['before'] . ' ';
86 + echo wp_kses_post( $this->settings['before'] ) . ' ';
85 87 }
86 88
87 89 echo esc_html($property->property_type);
88 90
@@ -87,10 +89,10 @@
87 89 echo esc_html($property->property_type);
88 90
89 91 if ( isset($this->settings['after']) && !empty($this->settings['after']) )
90 92 {
91 - echo ' ' . $this->settings['after'];
93 + echo ' ' . wp_kses_post( $this->settings['after'] );
92 94 }
93 95
94 96 echo '</div>';
95 97 }
96 -}
98 +}