From 36fdad4ef20dddcce8b2fa43e711fe4ee8372e44 Mon Sep 17 00:00:00 2001 From: Shail Mehta Date: Sat, 28 Feb 2026 09:41:13 +0530 Subject: [PATCH 01/10] Used wp_kses_post() Instead of esc_html() --- src/wp-includes/link-template.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/wp-includes/link-template.php b/src/wp-includes/link-template.php index 3b72ff6351ad7..0bae1a3bebe4b 100644 --- a/src/wp-includes/link-template.php +++ b/src/wp-includes/link-template.php @@ -4820,7 +4820,7 @@ function get_the_privacy_policy_link( $before = '', $after = '' ) { $link = sprintf( '%s', esc_url( $privacy_policy_url ), - esc_html( $page_title ) + wp_kses_post( $page_title ) ); } From 88368d84af07a601729f08107e5eaae645f90e84 Mon Sep 17 00:00:00 2001 From: Shail Mehta Date: Sat, 25 Jul 2026 10:02:30 +0530 Subject: [PATCH 02/10] Apply Feedback Changes --- src/wp-admin/comment.php | 18 +- src/wp-admin/edit-form-comment.php | 16 +- .../includes/class-walker-nav-menu-edit.php | 16 +- .../includes/class-wp-comments-list-table.php | 15 +- .../includes/dashboard-on-this-day.php | 11 +- .../themes/twentytwentyone/image.php | 11 +- src/wp-includes/blocks/latest-posts.php | 11 +- src/wp-includes/link-template.php | 12 +- .../tests/link/getThePrivacyPolicyLink.php | 358 ++++++++++-------- 9 files changed, 287 insertions(+), 181 deletions(-) diff --git a/src/wp-admin/comment.php b/src/wp-admin/comment.php index b834f7b594062..8c914cb67f210 100644 --- a/src/wp-admin/comment.php +++ b/src/wp-admin/comment.php @@ -202,12 +202,23 @@ comment_post_ID; + $post_id = $comment->comment_post_ID; + $post_title = wp_kses( + get_the_title( $post_id ), + array( + 'strong' => array(), + 'em' => array(), + 'b' => array(), + 'i' => array(), + 'span' => array(), + + ) + ); if ( current_user_can( 'edit_post', $post_id ) ) { $post_link = ""; - $post_link .= esc_html( get_the_title( $post_id ) ) . ''; + $post_link .= $post_title . ''; } else { - $post_link = esc_html( get_the_title( $post_id ) ); + $post_link = $post_title; } echo $post_link; @@ -223,6 +234,7 @@ } ?> + diff --git a/src/wp-admin/edit-form-comment.php b/src/wp-admin/edit-form-comment.php index 375dd61ad955e..ee93052d42ac9 100644 --- a/src/wp-admin/edit-form-comment.php +++ b/src/wp-admin/edit-form-comment.php @@ -181,12 +181,22 @@ comment_post_ID; +$post_id = $comment->comment_post_ID; +$post_title = wp_kses( + get_the_title( $post_id ), + array( + 'strong' => array(), + 'em' => array(), + 'b' => array(), + 'i' => array(), + 'span' => array(), + ) +); if ( current_user_can( 'edit_post', $post_id ) ) { $post_link = ""; - $post_link .= esc_html( get_the_title( $post_id ) ) . ''; + $post_link .= $post_title . ''; } else { - $post_link = esc_html( get_the_title( $post_id ) ); + $post_link = $post_title; } ?> diff --git a/src/wp-admin/includes/class-walker-nav-menu-edit.php b/src/wp-admin/includes/class-walker-nav-menu-edit.php index a287a7c4b8cdd..a1907083009c9 100644 --- a/src/wp-admin/includes/class-walker-nav-menu-edit.php +++ b/src/wp-admin/includes/class-walker-nav-menu-edit.php @@ -293,8 +293,22 @@ public function start_el( &$output, $data_object, $depth = 0, $args = null, $cur type && false !== $original_title ) : ?> diff --git a/src/wp-admin/includes/class-wp-comments-list-table.php b/src/wp-admin/includes/class-wp-comments-list-table.php index 2b927a7f81a6a..50124408ce19b 100644 --- a/src/wp-admin/includes/class-wp-comments-list-table.php +++ b/src/wp-admin/includes/class-wp-comments-list-table.php @@ -1119,11 +1119,22 @@ public function column_response( $comment ) { $this->pending_count[ $post->ID ] = $pending_comments; } + $post_title = wp_kses( + get_the_title( $post->ID ), + array( + 'strong' => array(), + 'em' => array(), + 'b' => array(), + 'i' => array(), + 'span' => array(), + ) + ); + if ( current_user_can( 'edit_post', $post->ID ) ) { $post_link = ""; - $post_link .= esc_html( get_the_title( $post->ID ) ) . ''; + $post_link .= $post_title . ''; } else { - $post_link = esc_html( get_the_title( $post->ID ) ); + $post_link = $post_title; } echo '