From a55f247ebb989687eb86c35745476b92db2ecec4 Mon Sep 17 00:00:00 2001 From: Brian Miyaji Date: Sun, 7 Jun 2020 01:00:17 +1000 Subject: [PATCH] Sanitize delimiter setting --- includes/admin/settings/class-sp-settings-events.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/includes/admin/settings/class-sp-settings-events.php b/includes/admin/settings/class-sp-settings-events.php index 4f638142..9371c751 100644 --- a/includes/admin/settings/class-sp-settings-events.php +++ b/includes/admin/settings/class-sp-settings-events.php @@ -5,7 +5,7 @@ * @author ThemeBoy * @category Admin * @package SportsPress/Admin - * @version 2.6.15 + * @version 2.7.1.2 */ if ( ! defined( 'ABSPATH' ) ) exit; // Exit if accessed directly @@ -469,7 +469,7 @@ class SP_Settings_Events extends SP_Settings_Page { parent::save(); if ( isset( $_POST['sportspress_event_teams_delimiter'] ) ) - update_option( 'sportspress_event_teams_delimiter', $_POST['sportspress_event_teams_delimiter'] ); + update_option( 'sportspress_event_teams_delimiter', sanitize_text_field( $_POST['sportspress_event_teams_delimiter'] ) ); } /**