From 6df81f3d95ef1dd36120f90f76fbef062a33568e Mon Sep 17 00:00:00 2001 From: nacin Date: Sat, 27 Feb 2010 20:26:37 +0000 Subject: [PATCH] Escape mod_$theme option name. see #9015 git-svn-id: http://svn.automattic.com/wordpress/trunk@13469 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-includes/theme.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/wp-includes/theme.php b/wp-includes/theme.php index 6168facfcc..5375ab31f6 100644 --- a/wp-includes/theme.php +++ b/wp-includes/theme.php @@ -1200,7 +1200,7 @@ function validate_current_theme() { function get_theme_mod($name, $default = false) { $theme = get_current_theme(); - $mods = get_option("mods_$theme"); + $mods = get_option( esc_sql( "mods_$theme" ) ); if ( isset($mods[$name]) ) return apply_filters( "theme_mod_$name", $mods[$name] );