From fd1dfbc113694bbdd131ee14a7a6b67815beece4 Mon Sep 17 00:00:00 2001 From: Peter Wilson Date: Wed, 12 Jul 2023 05:21:23 +0000 Subject: [PATCH] General: Escape nonce used for block theme activation. Add `wp_json_encode()` as an escaping function when setting the `WP_BLOCK_THEME_ACTIVATE_NONCE` global on the block theme preview screen. This account for custom nonce implementations making use of special characters that require escaping in JavaScript strings. Props antonvlasenko, ramonopoly. Fixes #58712. Built from https://develop.svn.wordpress.org/trunk@56218 git-svn-id: http://core.svn.wordpress.org/trunk@55730 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-includes/theme-previews.php | 2 +- wp-includes/version.php | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/wp-includes/theme-previews.php b/wp-includes/theme-previews.php index d9325ddbf3..e8e4a6a8c8 100644 --- a/wp-includes/theme-previews.php +++ b/wp-includes/theme-previews.php @@ -70,7 +70,7 @@ function wp_block_theme_activate_nonce() { $nonce_handle = 'switch-theme_' . wp_get_theme_preview_path(); ?>