General: Use correct escaping function for form action attributes.

Props chintan1896, audrasjb.
Fixes #53150.

git-svn-id: https://develop.svn.wordpress.org/trunk@50809 602fd350-edb4-49c9-b593-d223f7449a82
This commit is contained in:
Jonathan Desrosiers
2021-05-04 13:46:06 +00:00
parent 3eb51f7546
commit 80302b7b35

View File

@@ -2258,7 +2258,7 @@ function the_block_editor_meta_boxes() {
<form class="metabox-base-form">
<?php the_block_editor_meta_box_post_form_hidden_fields( $post ); ?>
</form>
<form id="toggle-custom-fields-form" method="post" action="<?php echo esc_attr( admin_url( 'post.php' ) ); ?>">
<form id="toggle-custom-fields-form" method="post" action="<?php echo esc_url( admin_url( 'post.php' ) ); ?>">
<?php wp_nonce_field( 'toggle-custom-fields', 'toggle-custom-fields-nonce' ); ?>
<input type="hidden" name="action" value="toggle-custom-fields" />
</form>