From 7a11e847751cf74b9d3e60acfc6a2860b1e8f20e Mon Sep 17 00:00:00 2001 From: Ryan Boren Date: Sun, 1 Mar 2009 19:57:37 +0000 Subject: [PATCH] Escape hyphen in regex. Props chrisbliss18. fixes #8548 #9244 git-svn-id: https://develop.svn.wordpress.org/trunk@10676 602fd350-edb4-49c9-b593-d223f7449a82 --- wp-includes/theme.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/wp-includes/theme.php b/wp-includes/theme.php index 4634075a83..22e46bc876 100644 --- a/wp-includes/theme.php +++ b/wp-includes/theme.php @@ -849,7 +849,7 @@ function preview_theme() { if ( !current_user_can( 'switch_themes' ) ) return; - $_GET['template'] = preg_replace('|[^a-z0-9_.-/]|i', '', $_GET['template']); + $_GET['template'] = preg_replace('|[^a-z0-9_.\-/]|i', '', $_GET['template']); if ( validate_file($_GET['template']) ) return; @@ -857,7 +857,7 @@ function preview_theme() { add_filter('template', create_function('', "return '{$_GET['template']}';") ); if ( isset($_GET['stylesheet']) ) { - $_GET['stylesheet'] = preg_replace('|[^a-z0-9_.-/]|i', '', $_GET['stylesheet']); + $_GET['stylesheet'] = preg_replace('|[^a-z0-9_.\-/]|i', '', $_GET['stylesheet']); if ( validate_file($_GET['stylesheet']) ) return; add_filter('stylesheet', create_function('', "return '{$_GET['stylesheet']}';") );