From 4841d5948b290c9b9e90ab8cafc65c79f4f99c71 Mon Sep 17 00:00:00 2001 From: Savvas Hadjigeorgiou Date: Fri, 5 Nov 2021 13:21:58 +0200 Subject: [PATCH] Escape several output vars at Admin Settings page --- includes/admin/class-sp-admin-settings.php | 56 +++++++++++----------- 1 file changed, 28 insertions(+), 28 deletions(-) diff --git a/includes/admin/class-sp-admin-settings.php b/includes/admin/class-sp-admin-settings.php index 87d543be..cc0f400f 100644 --- a/includes/admin/class-sp-admin-settings.php +++ b/includes/admin/class-sp-admin-settings.php @@ -252,7 +252,7 @@ class SP_Admin_Settings { if ( $tip && in_array( $value['type'], array( 'checkbox' ) ) ) { - $tip = '

' . $tip . '

'; + $tip = '

' . esc_attr( $tip ) . '

'; } elseif ( $tip ) { @@ -311,9 +311,9 @@ class SP_Admin_Settings { ?> - + - + - /> + /> - + - - + +