diff --git a/src/wp-includes/link-template.php b/src/wp-includes/link-template.php
index 3d4ffc23b8f62..a70bae8936b6e 100644
--- a/src/wp-includes/link-template.php
+++ b/src/wp-includes/link-template.php
@@ -4848,7 +4848,18 @@ function get_the_privacy_policy_link( $before = '', $after = '' ) {
$link = sprintf(
'%s',
esc_url( $privacy_policy_url ),
- esc_html( $page_title )
+ wp_kses(
+ $page_title,
+ array(
+ 'strong' => array(),
+ 'em' => array(),
+ 'b' => array(),
+ 'i' => array(),
+ 'span' => array(
+ 'class' => true,
+ ),
+ )
+ )
);
}
diff --git a/tests/phpunit/tests/link/getThePrivacyPolicyLink.php b/tests/phpunit/tests/link/getThePrivacyPolicyLink.php
index ca489bf177d7c..903c3fb70907e 100644
--- a/tests/phpunit/tests/link/getThePrivacyPolicyLink.php
+++ b/tests/phpunit/tests/link/getThePrivacyPolicyLink.php
@@ -78,6 +78,37 @@ public function test_get_the_privacy_policy_link_should_return_valid_link_when_p
$this->assertStringEndsWith( '>' . WP_TESTS_DOMAIN . ' Privacy Policy', $actual_link );
}
+ /**
+ * The function should allow only supported formatting in the privacy policy page title.
+ *
+ * @ticket 64748
+ */
+ public function test_get_the_privacy_policy_link_should_allow_supported_title_markup() {
+ $privacy_policy_page_id = self::$privacy_policy_page_id;
+
+ // Run after core `the_title` formatting filters (e.g. wptexturize).
+ $filter = static function ( $title, $post_id ) use ( $privacy_policy_page_id ) {
+ if ( (int) $privacy_policy_page_id === (int) $post_id ) {
+ return 'Privacy Policy Bold Italic Page ';
+ }
+
+ return $title;
+ };
+
+ add_filter( 'the_title', $filter, 20, 2 );
+
+ update_option( 'wp_page_for_privacy_policy', self::$privacy_policy_page_id );
+
+ $actual_link = get_the_privacy_policy_link();
+
+ remove_filter( 'the_title', $filter, 20 );
+
+ $this->assertStringEndsWith(
+ '>Privacy Policy Bold Italic Page alert("test")',
+ $actual_link
+ );
+ }
+
/**
* The function should prepend the supplied `$before` markup and append the
* supplied `$after` markup when the `wp_page_for_privacy_policy` is configured.