Add escaping to attributes

This commit is contained in:
Daniel Dudzic 2024-04-09 12:21:33 +02:00
parent 64bd0a2da8
commit 7672f66bcf
No known key found for this signature in database
GPG key ID: 31B40D33E3465483
2 changed files with 10 additions and 15 deletions

View file

@ -24,9 +24,9 @@ class PayLaterWCBlocksRenderer {
* @param ContainerInterface $c
* @return string|void
*/
public function render( array $attributes, string $location, ContainerInterface $c ) {
public function render( array $attributes, string $location, ContainerInterface $c ) {
if ( PayLaterWCBlocksModule::is_placement_enabled( $c->get( 'wcgateway.settings.status' ), $location ) ) {
return '<div id="' . htmlspecialchars($attributes['id'] ?? '') . '" class="ppcp-messages" data-partner-attribution-id="Woo_PPCP"></div>';
return '<div id="' . esc_attr( $attributes['id'] ?? '' ) . '" class="ppcp-messages" data-partner-attribution-id="Woo_PPCP"></div>';
}
}
}