diff --git a/includes/admin/class-sp-admin-dashboard.php b/includes/admin/class-sp-admin-dashboard.php
index bafd2ddd..570ec260 100644
--- a/includes/admin/class-sp-admin-dashboard.php
+++ b/includes/admin/class-sp-admin-dashboard.php
@@ -54,7 +54,7 @@ class SP_Admin_Dashboard {
else:
$output = '' . $text . '';
endif;
- echo '
' . $output . '';
+ echo '' . esc_html( $output ) . '';
endif;
endforeach;
return $items;
diff --git a/includes/admin/settings/class-sp-settings-status.php b/includes/admin/settings/class-sp-settings-status.php
index eae3cb45..d57028fd 100644
--- a/includes/admin/settings/class-sp-settings-status.php
+++ b/includes/admin/settings/class-sp-settings-status.php
@@ -245,7 +245,7 @@ class SP_Settings_Status extends SP_Settings_Page {
if ( sizeof( $sp_plugins ) == 0 )
echo '-';
else
- echo implode( ',
', $sp_plugins );
+ echo implode( ',
', array_map( 'wp_kses_post', $sp_plugins ) );
?>
@@ -510,8 +510,8 @@ class SP_Settings_Status extends SP_Settings_Page {
if ( $found_files ) {
foreach ( $found_files as $plugin_name => $found_plugin_files ) {
?>
- (): |
- ', $found_plugin_files ); ?> |
+ (): |
+ ', array_map( 'wp_kses_post', $found_plugin_files ) ); ?> |
$label ): ?>
-
+
@@ -898,7 +898,7 @@ class SP_AJAX {
$field_id = 'columns';
?>
-
+
@@ -1152,7 +1152,7 @@ class SP_AJAX {
-
+
diff --git a/includes/class-sp-template-loader.php b/includes/class-sp-template-loader.php
index 5778ec15..710180e4 100644
--- a/includes/class-sp-template-loader.php
+++ b/includes/class-sp-template-loader.php
@@ -78,7 +78,7 @@ class SP_Template_Loader {
if ( 'yes' !== get_option( $template['option'], sp_array_value( $template, 'default', 'yes' ) ) ) continue;
// Render the template
- echo '
';
+ echo '
';
if ( 'content' === $key ) {
echo wp_kses_post( $content );
// Template content hook
diff --git a/includes/widgets/class-sp-widget-birthdays.php b/includes/widgets/class-sp-widget-birthdays.php
index 270cfe22..b656d055 100644
--- a/includes/widgets/class-sp-widget-birthdays.php
+++ b/includes/widgets/class-sp-widget-birthdays.php
@@ -77,7 +77,7 @@ class SP_Widget_Birthdays extends WP_Widget {