← All changes
|
modules/gutenberg/dist/blocks/image/class-spec-image.php
+12
-4
0.0.13
→
2.12.8
View file →
| @@ -782,13 +782,21 @@ | ||
| 782 | 782 | $image_heading = ''; |
| 783 | 783 | |
| 784 | 784 | if ( ! empty( $attributes['heading'] ) ) { |
| 785 | 785 | |
| 786 | - $heading_id = isset( $attributes['headingId'] ) ? ' id="' . $attributes['headingId'] . '"' : ''; | |
| 786 | + // Validate the tag-name attribute against the editor UI options | |
| 787 | + // (esc_html() does not strip spaces or `=`, which is unsafe when | |
| 788 | + // echoed in tag-name position). | |
| 789 | + $allowed_heading_tags = [ 'h1', 'h2', 'h3', 'h4', 'h5', 'h6' ]; | |
| 790 | + $heading_tag = isset( $attributes['headingTag'] ) && in_array( $attributes['headingTag'], $allowed_heading_tags, true ) | |
| 791 | + ? $attributes['headingTag'] | |
| 792 | + : 'h2'; | |
| 793 | + | |
| 794 | + $heading_id = ! empty( $attributes['headingId'] ) ? ' id="' . esc_attr( $attributes['headingId'] ) . '"' : ''; | |
| 787 | 795 | $image_heading = sprintf( |
| 788 | 796 | '<%1$s%2$s class="uagb-image-heading">%3$s</%1$s>', |
| 789 | - esc_html( $attributes['headingTag'] ), | |
| 790 | - esc_attr( $heading_id ), | |
| 797 | + esc_html( $heading_tag ), | |
| 798 | + $heading_id, | |
| 791 | 799 | esc_html( $attributes['heading'] ) |
| 792 | 800 | ); |
| 793 | 801 | } |
| 794 | 802 | |
| @@ -825,9 +833,9 @@ | ||
| 825 | 833 | } |
| 826 | 834 | |
| 827 | 835 | ob_start(); |
| 828 | 836 | ?> |
| 829 | - <div class="<?php echo esc_attr( implode( ' ', $main_classes ) ); ?>"> | |
| 837 | + <div data-block-id="<?php echo esc_attr( $block_id ); ?>" class="<?php echo esc_attr( implode( ' ', $main_classes ) ); ?>"> | |
| 830 | 838 | <figure class="wp-block-uagb-image__figure"> |
| 831 | 839 | <?php echo wp_kses( $figure_image, 'post' ); ?> |
| 832 | 840 | |
| 833 | 841 | <?php if ( 'overlay' === $attributes['layout'] ) : ?> |