Skip to content

Commit 5c89475

Browse files
Merge pull request #1083 from Codeinwp/bugfix/optimole-service/1711
Escaped URLs to prevent XSS
2 parents cce692c + 5de34a5 commit 5c89475

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

inc/url_replacer.php

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -163,6 +163,10 @@ public function build_url(
163163
$url = sprintf( '%s://%s', is_ssl() ? 'https' : 'http', $url );
164164
}
165165
$normalized_ext = strtolower( $ext );
166+
$url = esc_url( $url );
167+
if ( empty( $url ) ) {
168+
return $original_url;
169+
}
166170
if ( isset( Optml_Config::$image_extensions[ $normalized_ext ] ) ) {
167171
$new_url = $this->normalize_image( $url, $original_url, $args, $is_uploaded, $normalized_ext );
168172
if ( $is_uploaded ) {

0 commit comments

Comments
 (0)