| @@ -50,9 +50,9 @@ | ||
| 50 | 50 | public function retrieve_show_message($key, $echo = false) { |
| 51 | 51 | if (empty($key) || !isset($this->translations[$key])) return ''; |
| 52 | 52 | |
| 53 | 53 | if ($echo) { |
| 54 | - echo $this->translations[$key]; | |
| 54 | + echo esc_html($this->translations[$key]); | |
| 55 | 55 | return; |
| 56 | 56 | } |
| 57 | 57 | |
| 58 | 58 | return $this->translations[$key]; |
| @@ -142,9 +142,9 @@ | ||
| 142 | 142 | } |
| 143 | 143 | |
| 144 | 144 | if (is_string($results)) { |
| 145 | 145 | // A handful of legacy methods, and some which are directly the source for iframes, for which JSON is not appropriate. |
| 146 | - echo $results; | |
| 146 | + echo $results; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- We don't escape here to avoid double escaping and keep the HTML code needed by the receiver of this request. | |
| 147 | 147 | } else { |
| 148 | 148 | echo json_encode($results); |
| 149 | 149 | } |
| 150 | 150 | die; |