From cbbba235308b0756c97649a58977b6148998e8bd Mon Sep 17 00:00:00 2001 From: Dominik Schilling Date: Mon, 18 Jul 2016 14:03:04 +0000 Subject: [PATCH] Comments: Use `wp_strip_all_tags()` to strip HTML tags. `wp_kses()` should only be used if you have a whitelist. Props rachelbaker. Fixes #37208. git-svn-id: https://develop.svn.wordpress.org/trunk@38092 602fd350-edb4-49c9-b593-d223f7449a82 --- src/wp-includes/comment.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/wp-includes/comment.php b/src/wp-includes/comment.php index ef4b553767..8edfc2859f 100644 --- a/src/wp-includes/comment.php +++ b/src/wp-includes/comment.php @@ -1057,7 +1057,7 @@ function wp_blacklist_check($author, $email, $url, $comment, $user_ip, $user_age return false; // If moderation keys are empty // Ensure HTML tags are not being used to bypass the blacklist. - $comment_without_html = wp_kses( $comment, array() ); + $comment_without_html = wp_strip_all_tags( $comment ); $words = explode("\n", $mod_keys );