Events Manager
#_LINKEDNAME placeholder can generate invalid HTML - needs to escape title (2 posts)

  1. Ross Wintle
    Posted 4 years ago #

    Hi Marcus,

    Wow - this forum keeps you busy. Definitely one of the best-supported plugins.

    Just drawing your attention to a tiny bug.

    Using the #_LINKEDNAME placeholder seems to generate code like:

    <a href='http://my.website/events/event/' title='Don't use apostrophe's here!'>Don't use apostrophe's here</a>

    Hopefully you'll see what I'm getting at. Attributes should be escaped using esc_attr()

    I think you fixed this recently for #_EVENTIMAGE, could you do the same for #_LINKEDNAME please?

    Perhaps you need to review where you're creating markup and ensure that you're always escaping attributes - a good habit which I've yet to develop myself!



  2. Marcus
    NetWebLogic Support
    Plugin Author

    Posted 4 years ago #

    Hi Ross, thanks for the kind words. A habit I've taken only recently too ;) but looking at the code the latest version should already have that implemented?

Topic Closed

This topic has been closed to new replies.

About this Plugin

  • Events Manager
  • Frequently Asked Questions
  • Support Threads
  • Reviews

About this Topic