Escaping $_POST

Implementing feedback from the WordPress Plugin Review Team, because I was sloppy. 🤦‍♂️
This commit is contained in:
Jason Cosper 2023-01-05 13:43:46 -08:00 committed by GitHub
parent d157b1fb26
commit c1df116b37
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -67,7 +67,7 @@ function biscotti_login_cookie_expiration_form_fields_update( $user_id )
if (! current_user_can('edit_user', $user_id) ) {
return;
}
update_user_meta($user_id, 'biscotti_login_cookie_expiration', $_POST['biscotti_login_cookie_expiration']);
update_user_meta($user_id, 'biscotti_login_cookie_expiration', esc_attr($_POST['biscotti_login_cookie_expiration']));
}
// Save the chosen login cookie expiration date when the user profile is updated.