From e89ac79c7c9d80de55d3e5709bd91e3ad557d9de Mon Sep 17 00:00:00 2001 From: savvasha Date: Sun, 7 Nov 2021 06:50:17 +0200 Subject: [PATCH] Escape using wp_kses_post() than esc_html() function --- includes/class-sp-shortcodes.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/includes/class-sp-shortcodes.php b/includes/class-sp-shortcodes.php index 84fae5b9..95e5ebfb 100644 --- a/includes/class-sp-shortcodes.php +++ b/includes/class-sp-shortcodes.php @@ -66,9 +66,9 @@ class SP_Shortcodes { $before = empty( $wrapper['before'] ) ? '
' : $wrapper['before']; $after = empty( $wrapper['after'] ) ? '
' : $wrapper['after']; - echo esc_html( $before ); + echo wp_kses_post( $before ); call_user_func( $function, $atts ); - echo esc_html( $after ); + echo wp_kses_post( $after ); return ob_get_clean(); }