Thread Starter
lllor
(@lllor)
No, there is no issue concerning SQL injection.
I’ve just noticed that you added an esc_url() on $_POST… 🙂
-
This reply was modified 8 years, 10 months ago by lllor.
Thread Starter
lllor
(@lllor)
Yes. It’s working now 😉
Anyway, I see there was also a probable SQL injection issue…
-
This reply was modified 8 years, 10 months ago by lllor.
Thread Starter
lllor
(@lllor)
I suppose that line 209 $image_urls = $_POST[‘urls’] is the origin of the issue.
I don’t understand the aim of the function get_images_url() and the two actions wp_ajax_lightbox_description and wp_ajax_nopriv_lightbox_description (I can’t see any do_action related)