← All changes
|
modules/gutenberg/dist/blocks/advanced-heading/class-advanced-heading.php
+12
-2
2.8.1
→
2.12.8
View file →
| @@ -663,10 +663,20 @@ | ||
| 663 | 663 | if ( isset( $attributes['headingWrapper'] ) ) { |
| 664 | 664 | $heading_wrapper = $attributes['headingWrapper']; |
| 665 | 665 | } |
| 666 | 666 | |
| 667 | - $element = ! empty( $heading_wrapper ) ? $heading_wrapper : 'div'; | |
| 667 | + // Validate tag-name attributes against the editor UI options to prevent | |
| 668 | + // arbitrary HTML injection in tag-name position (esc_attr() does not strip | |
| 669 | + // `<`, `>`, spaces or `=`, which is unsafe when echoed as a tag name). | |
| 670 | + $allowed_wrapper_tags = [ 'div', 'header' ]; | |
| 671 | + $allowed_heading_tags = [ 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'p', 'div' ]; | |
| 668 | 672 | |
| 673 | + $element = in_array( $heading_wrapper, $allowed_wrapper_tags, true ) ? $heading_wrapper : 'div'; | |
| 674 | + | |
| 675 | + $heading_tag = isset( $attributes['headingTag'] ) && in_array( $attributes['headingTag'], $allowed_heading_tags, true ) | |
| 676 | + ? $attributes['headingTag'] | |
| 677 | + : 'h2'; | |
| 678 | + | |
| 669 | 679 | $seperator = ''; |
| 670 | 680 | |
| 671 | 681 | if ( isset( $attributes['separatorStyle'] ) |
| 672 | 682 | && 'none' !== $attributes['separatorStyle'] |
| @@ -680,9 +690,9 @@ | ||
| 680 | 690 | $heading_text = 'above-heading' === $attributes['separatorPosition'] ? $seperator : ''; |
| 681 | 691 | $attributes['headingId'] = isset( $attributes['headingId'] ) ? "id='{$attributes['headingId']}'" : ''; |
| 682 | 692 | $heading_text .= sprintf( |
| 683 | 693 | '<%1$s class="uagb-heading-text" %3$s>%2$s</%1$s>', |
| 684 | - esc_attr( $attributes['headingTag'] ), | |
| 694 | + esc_attr( $heading_tag ), | |
| 685 | 695 | $attributes['headingTitle'], |
| 686 | 696 | esc_attr( $attributes['headingId'] ) |
| 687 | 697 | ); |
| 688 | 698 | $heading_text .= 'below-heading' === $attributes['separatorPosition'] ? $seperator : ''; |