From bc92bb0cbae3969dc53056efaed3593c66e2600a Mon Sep 17 00:00:00 2001 From: Colin Stewart Date: Wed, 30 Aug 2023 20:23:18 +0000 Subject: [PATCH] General: Replace two `esc_url_raw()` calls in core with `sanitize_url()`. This aims to improve performance by calling `sanitize_url()` directly, instead of the `esc_url_raw()` wrapper. As of WordPress 6.1, `sanitize_url()` is the recommended function for sanitizing a URL for database or redirect usage. This replaces the two remaining instances of `esc_url_raw()` with `sanitize_url()` in WordPress core. Follow-up to [53455], [53933], [54522]. Props rajinsharwar, SergeyBiryukov. Fixes #59247. git-svn-id: https://develop.svn.wordpress.org/trunk@56494 602fd350-edb4-49c9-b593-d223f7449a82 --- src/wp-includes/functions.php | 2 +- src/wp-includes/update.php | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/src/wp-includes/functions.php b/src/wp-includes/functions.php index d2304f4d55..be03264455 100644 --- a/src/wp-includes/functions.php +++ b/src/wp-includes/functions.php @@ -3613,7 +3613,7 @@ function wp_nonce_ays( $action ) { if ( wp_get_referer() ) { $wp_http_referer = remove_query_arg( 'updated', wp_get_referer() ); - $wp_http_referer = wp_validate_redirect( esc_url_raw( $wp_http_referer ) ); + $wp_http_referer = wp_validate_redirect( sanitize_url( $wp_http_referer ) ); $html .= '

'; $html .= sprintf( diff --git a/src/wp-includes/update.php b/src/wp-includes/update.php index 7c4e31feef..c5349832ac 100644 --- a/src/wp-includes/update.php +++ b/src/wp-includes/update.php @@ -754,7 +754,7 @@ function wp_update_themes( $extra_stats = array() ) { continue; } - $hostname = wp_parse_url( esc_url_raw( $theme_data['UpdateURI'] ), PHP_URL_HOST ); + $hostname = wp_parse_url( sanitize_url( $theme_data['UpdateURI'] ), PHP_URL_HOST ); /** * Filters the update response for a given theme hostname.