Skip to content

Commit dfabb3b

Browse files
committed
Add escaping on active class
1 parent 9063e30 commit dfabb3b

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

src/wp-admin/themes.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -432,7 +432,7 @@
432432
$active_class = ' active';
433433
}
434434
?>
435-
<div class="theme<?php echo $active_class; ?>">
435+
<div class="theme<?php echo esc_attr( $active_class ); ?>">
436436
<?php if ( ! empty( $theme['screenshot'][0] ) ) { ?>
437437
<div class="theme-screenshot">
438438
<img src="<?php echo esc_url( $theme['screenshot'][0] . '?ver=' . $theme['version'] ); ?>" alt="" />

0 commit comments

Comments
 (0)