Commit 9808e60e09 for wordpress.org
commit 9808e60e0971657c3c62d2efdc2d16e2922e18aa
Author: peterwilsoncc <peterwilsoncc@git.wordpress.org>
Date: Mon Oct 5 03:15:53 2026 +0000
Privacy: Correctly escape page title in `get_the_privacy_policy_link()`.
Update the escaping of the page title used in `get_the_privacy_policy_link()` to use a sub-set of permitted tags via `wp_kses()` rather than `esc_html()`.
WordPress permits the use of HTML tags within a page title so `esc_html()` isn't appropriate as it renders the HTML tags with html encoded characters.
Props shailu25, huzaifaalmesbah, mukesh27, hbhalodia, joedolson, masteradhoc, noruzzaman, ozgursar, sabernhardt, westonruter, wildworks.
Fixes #64748.
Built from https://develop.svn.wordpress.org/trunk@64092
git-svn-id: http://core.svn.wordpress.org/trunk@63251 1a063a9b-81f0-0310-95a4-ce76da25c4cd
diff --git a/wp-includes/link-template.php b/wp-includes/link-template.php
index 3d4ffc23b8..6d334d5e9e 100644
--- a/wp-includes/link-template.php
+++ b/wp-includes/link-template.php
@@ -4848,7 +4848,16 @@ function get_the_privacy_policy_link( $before = '', $after = '' ) {
$link = sprintf(
'<a class="privacy-policy-link" href="%s" rel="privacy-policy">%s</a>',
esc_url( $privacy_policy_url ),
- esc_html( $page_title )
+ wp_kses(
+ $page_title,
+ array(
+ 'strong' => array( 'class' => true ),
+ 'em' => array( 'class' => true ),
+ 'b' => array( 'class' => true ),
+ 'i' => array( 'class' => true ),
+ 'span' => array( 'class' => true ),
+ )
+ )
);
}
diff --git a/wp-includes/version.php b/wp-includes/version.php
index 629d0462a4..5f86109a7b 100644
--- a/wp-includes/version.php
+++ b/wp-includes/version.php
@@ -16,7 +16,7 @@
*
* @global string $wp_version
*/
-$wp_version = '7.2-alpha-64091';
+$wp_version = '7.2-alpha-64092';
/**
* Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.