Skip to content

Commit 7c5d98f

Browse files
committed
Unslashing level names in the wizard
1 parent 27ae590 commit 7c5d98f

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

adminpages/wizard/save-steps.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -163,7 +163,7 @@ function pmpro_init_save_wizard_data() {
163163
// If free level option is enabled, then get data.
164164
if ( ! empty( $_REQUEST['pmpro-wizard__free-level'] ) ) {
165165

166-
$free_level_name = ! empty( $_REQUEST['pmpro-wizard__free-level-name'] ) ? sanitize_text_field( $_REQUEST['pmpro-wizard__free-level-name'] ) : sanitize_text_field( __( 'Free', 'paid-memberships-pro' ) );
166+
$free_level_name = ! empty( $_REQUEST['pmpro-wizard__free-level-name'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['pmpro-wizard__free-level-name'] ) ) : sanitize_text_field( __( 'Free', 'paid-memberships-pro' ) );
167167

168168
$levels_array['free'] = array(
169169
'id' => 0,
@@ -185,7 +185,7 @@ function pmpro_init_save_wizard_data() {
185185

186186
if ( ! empty( $_REQUEST['pmpro-wizard__paid-level'] ) ) {
187187

188-
$paid_level_name = ! empty( $_REQUEST['pmpro-wizard__paid-level-name'] ) ? sanitize_text_field( $_REQUEST['pmpro-wizard__paid-level-name'] ) : sanitize_text_field( __( 'Premium', 'paid-memberships-pro' ) );
188+
$paid_level_name = ! empty( $_REQUEST['pmpro-wizard__paid-level-name'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['pmpro-wizard__paid-level-name'] ) ) : sanitize_text_field( __( 'Premium', 'paid-memberships-pro' ) );
189189
$amount = ! empty( $_REQUEST['pmpro-wizard__paid-level-amount'] ) ? floatval( $_REQUEST['pmpro-wizard__paid-level-amount'] ) : 10.00;
190190
$period = ! empty( $_REQUEST['cycle_period'] ) ? sanitize_text_field( $_REQUEST['cycle_period'] ) : 'Month';
191191

0 commit comments

Comments
 (0)