Skip to content

Commit d38848b

Browse files
committed
Add escaping
1 parent bccb9c1 commit d38848b

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

src/wp-login.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -231,7 +231,7 @@ function login_header( $title = null, $message = '', $wp_error = null ) {
231231
$message = apply_filters( 'login_message', $message );
232232

233233
if ( ! empty( $message ) ) {
234-
echo $message . "\n";
234+
echo wp_kses_post( $message ) . "\n";
235235
}
236236

237237
// In case a plugin uses $error rather than the $wp_errors object.

0 commit comments

Comments
 (0)