Skip to content

Commit 843e486

Browse files
committed
Networks and Sites: Sanitize key parameter in wp-activate.php.
Props khushipatel15. Fixes #63320. git-svn-id: https://develop.svn.wordpress.org/trunk@60204 602fd350-edb4-49c9-b593-d223f7449a82
1 parent d985e8f commit 843e486

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

src/wp-activate.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,9 +29,9 @@
2929
if ( isset( $_GET['key'] ) && isset( $_POST['key'] ) && $_GET['key'] !== $_POST['key'] ) {
3030
wp_die( __( 'A key value mismatch has been detected. Please follow the link provided in your activation email.' ), __( 'An error occurred during the activation' ), 400 );
3131
} elseif ( ! empty( $_GET['key'] ) ) {
32-
$key = $_GET['key'];
32+
$key = sanitize_text_field( $_GET['key'] );
3333
} elseif ( ! empty( $_POST['key'] ) ) {
34-
$key = $_POST['key'];
34+
$key = sanitize_text_field( $_POST['key'] );
3535
}
3636

3737
if ( $key ) {

0 commit comments

Comments
 (0)