mirror of
https://github.com/gosticks/wordpress-develop.git
synced 2026-06-28 14:20:15 +00:00
Use wpdb->escape instead of addslashes to prepare DB bound data.
git-svn-id: https://develop.svn.wordpress.org/trunk@2699 602fd350-edb4-49c9-b593-d223f7449a82
This commit is contained in:
@@ -24,9 +24,9 @@ $comment_content = trim($_POST['comment']);
|
||||
// If the user is logged in
|
||||
get_currentuserinfo();
|
||||
if ( $user_ID ) :
|
||||
$comment_author = addslashes($user_identity);
|
||||
$comment_author_email = addslashes($user_email);
|
||||
$comment_author_url = addslashes($user_url);
|
||||
$comment_author = $wpdb->escape($user_identity);
|
||||
$comment_author_email = $wpdb->escape($user_email);
|
||||
$comment_author_url = $wpdb->escape($user_url);
|
||||
else :
|
||||
if ( get_option('comment_registration') )
|
||||
die( __('Sorry, you must be logged in to post a comment.') );
|
||||
|
||||
Reference in New Issue
Block a user