Skip to content

Commit 6aee7ae

Browse files
committed
vulnerability fix
1 parent 4d2de93 commit 6aee7ae

File tree

1 file changed

+5
-2
lines changed

1 file changed

+5
-2
lines changed

lib/classes/class-settings.php

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -515,11 +515,14 @@ public function setup_wizard_interface() {
515515
public function save_media_settings(){
516516
if(isset($_POST['action']) && $_POST['action'] == 'stateless_settings' && wp_verify_nonce( $_POST['_smnonce'], 'wp-stateless-settings' )){
517517

518-
$settings = apply_filters('stateless::settings::save', sanitize_text_field($_POST['sm']));
518+
$settings = apply_filters('stateless::settings::save', $_POST['sm']);
519519
$root_dir_value = false;
520520

521521
foreach ( $settings as $name => $value ) {
522-
522+
/**
523+
* Sanitize POST data
524+
*/
525+
$value = sanitize_text_field($value);
523526
/**
524527
* root_dir settings
525528
*/

0 commit comments

Comments
 (0)