PluginProbe
Property Hive / 2.4.0
Property Hive v2.4.0
2.4.0 2.3.1 2.3.0 2.2.6 2.2.5 2.2.4 2.2.3 2.2.2 1.4.46 1.4.47 1.4.48 1.4.49 1.4.5 1.4.50 1.4.51 1.4.52 1.4.53 1.4.54 1.4.55 1.4.56 1.4.57 1.4.58 1.4.59 1.4.6 1.4.60 All 262 releases
← All changes | templates/single-property/description.php +6 -2 2.2.2 → 2.4.0 View file →
@@ -10,11 +10,12 @@
10 10 if ( ! defined( 'ABSPATH' ) ) exit; // Exit if accessed directly
11 11
12 12 global $post, $property;
13 13
14 +// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound -- Template-local variable; the template is included through a helper/function scope, so PrefixAllGlobals misclassifies the file when checked standalone.
14 15 $description = $property->get_formatted_description();
15 16
16 -if ( trim(strip_tags($description)) != '' )
17 +if ( trim(wp_strip_all_tags($description)) != '' )
17 18 {
18 19 ?>
19 20 <div class="description">
20 21
@@ -19,10 +20,13 @@
19 20 <div class="description">
20 21
21 22 <h4><?php echo esc_html(__( 'Full Details', 'propertyhive' )); ?></h4>
22 23
23 - <div class="description-contents"><?php echo $description; ?></div>
24 + <div class="description-contents"><?php
25 + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Stored description fields are sanitized before the trusted propertyhive_get_detail and propertyhive_description_output HTML extension hooks; preserve their embed output.
26 + echo $description;
27 + ?></div>
24 28
25 29 </div>
26 30 <?php
27 31 }
28 32 ?>