WordPress.org

Ready to get started?Download WordPress

Forums

Events Manager
#_LINKEDNAME placeholder can generate invalid HTML - needs to escape title (2 posts)

  1. magicroundabout
    Member
    Posted 2 years ago #

    Hi Marcus,

    Wow - this forum keeps you busy. Definitely one of the best-supported plugins.

    Just drawing your attention to a tiny bug.

    Using the #_LINKEDNAME placeholder seems to generate code like:

    <a href='http://my.website/events/event/' title='Don't use apostrophe's here!'>Don't use apostrophe's here</a>

    Hopefully you'll see what I'm getting at. Attributes should be escaped using esc_attr()

    I think you fixed this recently for #_EVENTIMAGE, could you do the same for #_LINKEDNAME please?

    Perhaps you need to review where you're creating markup and ensure that you're always escaping attributes - a good habit which I've yet to develop myself!

    Ross

    http://wordpress.org/extend/plugins/events-manager/

  2. Marcus
    NetWebLogic Support
    Plugin Author

    Posted 2 years ago #

    Hi Ross, thanks for the kind words. A habit I've taken only recently too ;) but looking at the code the latest version should already have that implemented?

Topic Closed

This topic has been closed to new replies.

About this Plugin

About this Topic