PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.12.8
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.12.8
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
← All changes | modules/gutenberg/dist/blocks/advanced-heading/class-advanced-heading.php +12 -2 2.8.0 → 2.12.8 View file →
@@ -663,10 +663,20 @@
663 663 if ( isset( $attributes['headingWrapper'] ) ) {
664 664 $heading_wrapper = $attributes['headingWrapper'];
665 665 }
666 666
667 - $element = ! empty( $heading_wrapper ) ? $heading_wrapper : 'div';
667 + // Validate tag-name attributes against the editor UI options to prevent
668 + // arbitrary HTML injection in tag-name position (esc_attr() does not strip
669 + // `<`, `>`, spaces or `=`, which is unsafe when echoed as a tag name).
670 + $allowed_wrapper_tags = [ 'div', 'header' ];
671 + $allowed_heading_tags = [ 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'p', 'div' ];
668 672
673 + $element = in_array( $heading_wrapper, $allowed_wrapper_tags, true ) ? $heading_wrapper : 'div';
674 +
675 + $heading_tag = isset( $attributes['headingTag'] ) && in_array( $attributes['headingTag'], $allowed_heading_tags, true )
676 + ? $attributes['headingTag']
677 + : 'h2';
678 +
669 679 $seperator = '';
670 680
671 681 if ( isset( $attributes['separatorStyle'] )
672 682 && 'none' !== $attributes['separatorStyle']
@@ -680,9 +690,9 @@
680 690 $heading_text = 'above-heading' === $attributes['separatorPosition'] ? $seperator : '';
681 691 $attributes['headingId'] = isset( $attributes['headingId'] ) ? "id='{$attributes['headingId']}'" : '';
682 692 $heading_text .= sprintf(
683 693 '<%1$s class="uagb-heading-text" %3$s>%2$s</%1$s>',
684 - esc_attr( $attributes['headingTag'] ),
694 + esc_attr( $heading_tag ),
685 695 $attributes['headingTitle'],
686 696 esc_attr( $attributes['headingId'] )
687 697 );
688 698 $heading_text .= 'below-heading' === $attributes['separatorPosition'] ? $seperator : '';