diff --git a/src/wp-includes/pluggable.php b/src/wp-includes/pluggable.php index 39180c6513..9db601cb85 100644 --- a/src/wp-includes/pluggable.php +++ b/src/wp-includes/pluggable.php @@ -1412,7 +1412,7 @@ if ( ! function_exists( 'wp_validate_redirect' ) ) : * @return string redirect-sanitized URL */ function wp_validate_redirect( $location, $default = '' ) { - $location = trim( $location, " \t\n\r\0\x08\x0B" ); + $location = wp_sanitize_redirect( trim( $location, " \t\n\r\0\x08\x0B" ) ); // Browsers will assume 'http' is your protocol, and will obey a redirect to a URL starting with '//'. if ( '//' === substr( $location, 0, 2 ) ) { $location = 'http:' . $location;