WordPress.org

Ready to get started?Download WordPress

Forums

$content escaped - Shortcodes (3 posts)

  1. d0100
    Member
    Posted 2 years ago #

    Since $content is included in the return value without any escaping or encoding, the user can include raw HTML:

    [caption]My Caption[/caption]

    Which would produce:

    <span class="caption">My Caption</span>

    How come that is not true? The content is coming out escaped.

  2. d0100
    Member
    Posted 2 years ago #

    Anyone?

  3. Jackson
    Member
    Posted 2 years ago #

    The content will have had html entities encoded and be run through wptexturize when your shortcode gets the content.

    Here's how I reverse the escaping on output in my iframe shortcode plugin:

    http://jacksonwhelan.com/2011/09/simple-iframe-shortcode-plugin/

    Hope that helps.

Topic Closed

This topic has been closed to new replies.

About this Topic

Tags

No tags yet.