| @@ -70,12 +70,14 @@ | ||
| 70 | 70 | |
| 71 | 71 | // Add 'class' attribute to element root tag |
| 72 | 72 | $this->set_attribute( '_root', 'class', $root_classes ); |
| 73 | 73 | |
| 74 | + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Bricks serializes registered attributes through its documented render_attributes() API. | |
| 74 | 75 | echo "<div {$this->render_attributes( '_root' )}>"; |
| 75 | 76 | |
| 76 | 77 | if ( isset( $this->settings['icon'] ) ) |
| 77 | 78 | { |
| 79 | + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Bricks Element::render_icon() returns the icon-control HTML fragment, including i/svg markup; Bricks sanitizes uploaded SVGs at its documented upload boundary. | |
| 78 | 80 | echo self::render_icon( $this->settings['icon'] ); |
| 79 | 81 | echo ' '; |
| 80 | 82 | } |
| 81 | 83 | |
| @@ -80,9 +82,9 @@ | ||
| 80 | 82 | } |
| 81 | 83 | |
| 82 | 84 | if ( isset($this->settings['before']) && !empty($this->settings['before']) ) |
| 83 | 85 | { |
| 84 | - echo $this->settings['before'] . ' '; | |
| 86 | + echo wp_kses_post( $this->settings['before'] ) . ' '; | |
| 85 | 87 | } |
| 86 | 88 | |
| 87 | 89 | echo esc_html($property->property_type); |
| 88 | 90 | |
| @@ -87,10 +89,10 @@ | ||
| 87 | 89 | echo esc_html($property->property_type); |
| 88 | 90 | |
| 89 | 91 | if ( isset($this->settings['after']) && !empty($this->settings['after']) ) |
| 90 | 92 | { |
| 91 | - echo ' ' . $this->settings['after']; | |
| 93 | + echo ' ' . wp_kses_post( $this->settings['after'] ); | |
| 92 | 94 | } |
| 93 | 95 | |
| 94 | 96 | echo '</div>'; |
| 95 | 97 | } |
| 96 | -} | |
| 98 | +} | |