From f1140ae187be1e3d37c3607f9a34646ff20e2eb4 Mon Sep 17 00:00:00 2001 From: Ryan Boren Date: Fri, 25 Jan 2008 02:21:59 +0000 Subject: [PATCH] Unescape user data before sending to wpdb::update() and wpdb::insert(), which expect unescaped data. git-svn-id: https://develop.svn.wordpress.org/trunk@6656 602fd350-edb4-49c9-b593-d223f7449a82 --- wp-includes/registration.php | 1 + 1 file changed, 1 insertion(+) diff --git a/wp-includes/registration.php b/wp-includes/registration.php index 48fb2b1c8f..343a887ef4 100644 --- a/wp-includes/registration.php +++ b/wp-includes/registration.php @@ -158,6 +158,7 @@ function wp_insert_user($userdata) { $user_registered = gmdate('Y-m-d H:i:s'); $data = compact( 'user_pass', 'user_email', 'user_url', 'user_nicename', 'display_name', 'user_registered' ); + $data = stripslashes_deep( $data ); if ( $update ) { $wpdb->update( $wpdb->users, $data, compact( 'ID' ) );