Skip to content

Commit 195d67d

Browse files
Pings/Trackbacks: Escape the XML error message in trackback_response().
Props maheshpatel, pbiron, sabernhardt, westonruter, SergeyBiryukov. Fixes #65047. git-svn-id: https://develop.svn.wordpress.org/trunk@62414 602fd350-edb4-49c9-b593-d223f7449a82
1 parent dd326c9 commit 195d67d

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

src/wp-trackback.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ function trackback_response( $error = 0, $error_message = '' ) {
3434
echo '<?xml version="1.0" encoding="utf-8"?' . ">\n";
3535
echo "<response>\n";
3636
echo "<error>1</error>\n";
37-
echo "<message>$error_message</message>\n";
37+
echo '<message>' . esc_xml( $error_message ) . "</message>\n";
3838
echo '</response>';
3939
die();
4040
} else {

0 commit comments

Comments
 (0)