From 9ca0c195c4083136ed4ff3b2550796b1a6e509e6 Mon Sep 17 00:00:00 2001 From: Brian Miyaji Date: Fri, 5 Nov 2021 22:24:14 +0900 Subject: [PATCH] Sanitize user registration fields --- modules/sportspress-user-registration.php | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/modules/sportspress-user-registration.php b/modules/sportspress-user-registration.php index e2bc5442..8ea979ac 100644 --- a/modules/sportspress-user-registration.php +++ b/modules/sportspress-user-registration.php @@ -97,8 +97,8 @@ class SportsPress_User_Registration { */ public static function register_form() { if ( 'yes' === get_option( 'sportspress_registration_name_inputs', 'no' ) ) { - $first_name = ( ! empty( $_POST['first_name'] ) ) ? trim( $_POST['first_name'] ) : ''; - $last_name = ( ! empty( $_POST['last_name'] ) ) ? trim( $_POST['last_name'] ) : ''; + $first_name = ( ! empty( $_POST['first_name'] ) ) ? trim( sanitize_text_field( $_POST['first_name'] ) ) : ''; + $last_name = ( ! empty( $_POST['last_name'] ) ) ? trim( sanitize_text_field( $_POST['last_name'] ) ) : ''; ?>