Skip to content

Validate file name and sanitize path after the filters and before the inclusion. #10

@widoz

Description

@widoz

In order to prevent third party code to hook and edit in wrong way the path for the template file I think a validation/sanitization may be useful for the path.

Also, we should be sure that the path belong to the wp-content/plugins or wp-content/themes/{current-active-theme} or the parent theme.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions