diff --git a/src/wp-includes/link-template.php b/src/wp-includes/link-template.php index 3d4ffc23b8f62..a70bae8936b6e 100644 --- a/src/wp-includes/link-template.php +++ b/src/wp-includes/link-template.php @@ -4848,7 +4848,18 @@ function get_the_privacy_policy_link( $before = '', $after = '' ) { $link = sprintf( '%s', esc_url( $privacy_policy_url ), - esc_html( $page_title ) + wp_kses( + $page_title, + array( + 'strong' => array(), + 'em' => array(), + 'b' => array(), + 'i' => array(), + 'span' => array( + 'class' => true, + ), + ) + ) ); } diff --git a/tests/phpunit/tests/link/getThePrivacyPolicyLink.php b/tests/phpunit/tests/link/getThePrivacyPolicyLink.php index ca489bf177d7c..903c3fb70907e 100644 --- a/tests/phpunit/tests/link/getThePrivacyPolicyLink.php +++ b/tests/phpunit/tests/link/getThePrivacyPolicyLink.php @@ -78,6 +78,37 @@ public function test_get_the_privacy_policy_link_should_return_valid_link_when_p $this->assertStringEndsWith( '>' . WP_TESTS_DOMAIN . ' Privacy Policy', $actual_link ); } + /** + * The function should allow only supported formatting in the privacy policy page title. + * + * @ticket 64748 + */ + public function test_get_the_privacy_policy_link_should_allow_supported_title_markup() { + $privacy_policy_page_id = self::$privacy_policy_page_id; + + // Run after core `the_title` formatting filters (e.g. wptexturize). + $filter = static function ( $title, $post_id ) use ( $privacy_policy_page_id ) { + if ( (int) $privacy_policy_page_id === (int) $post_id ) { + return 'Privacy Policy Bold Italic Page '; + } + + return $title; + }; + + add_filter( 'the_title', $filter, 20, 2 ); + + update_option( 'wp_page_for_privacy_policy', self::$privacy_policy_page_id ); + + $actual_link = get_the_privacy_policy_link(); + + remove_filter( 'the_title', $filter, 20 ); + + $this->assertStringEndsWith( + '>Privacy Policy Bold Italic Page alert("test")', + $actual_link + ); + } + /** * The function should prepend the supplied `$before` markup and append the * supplied `$after` markup when the `wp_page_for_privacy_policy` is configured.