/home/altere25/sportzsoft.altereddigital.com/wp-includes
NameSizeModeActions
assets/-0755rm
block-patterns/-0755rm
block-supports/-0755rm
blocks/-0755rm
certificates/-0755rm
css/-0755rm
customize/-0755rm
fonts/-0755rm
html-api/-0755rm
ID3/-0755rm
images/-0755rm
IXR/-0755rm
js/-0755rm
php-compat/-0755rm
PHPMailer/-0755rm
pomo/-0755rm
Requests/-0755rm
rest-api/-0755rm
SimplePie/-0755rm
sitemaps/-0755rm
sodium_compat/-0755rm
style-engine/-0755rm
Text/-0755rm
theme-compat/-0755rm
widgets/-0755rm
.htaccess1780644editdlrm
admin-bar.php359960644editdlrm
atomlib.php119500644editdlrm
author-template.php189510644editdlrm
block-editor.php279230644editdlrm
block-i18n.json3160644editdlrm
block-patterns.php129420644editdlrm
block-template-utils.php484840644editdlrm
block-template.php122880644editdlrm
blocks.php728840644editdlrm
bookmark-template.php129090644editdlrm
bookmark.php153780644editdlrm
cache-compat.php59690644editdlrm
cache.php134740644editdlrm
canonical.php344600644editdlrm
capabilities.php400260644editdlrm
category-template.php570030644editdlrm
category.php127090644editdlrm
class-feed.php5290644editdlrm
class-http.php3670644editdlrm
class-IXR.php25430644editdlrm
class-json.php436840644editdlrm
class-oembed.php4010644editdlrm
class-phpass.php67080644editdlrm
class-phpmailer.php6640644editdlrm
class-pop3.php209690644editdlrm
class-requests.php22370644editdlrm
class-simplepie.php981240644editdlrm
class-smtp.php4570644editdlrm
class-snoopy.php377150644editdlrm
class-walker-category-dropdown.php24690644editdlrm
class-walker-category.php84770644editdlrm
class-walker-comment.php142130644editdlrm
class-walker-nav-menu.php113130644editdlrm
class-walker-page-dropdown.php27100644editdlrm
class-walker-page.php76120644editdlrm
class-wp-admin-bar.php173640644editdlrm
class-wp-ajax-response.php52660644editdlrm
class-wp-application-passwords.php128540644editdlrm
class-wp-block-editor-context.php13500644editdlrm
class-wp-block-list.php47730644editdlrm
class-wp-block-parser-block.php25550644editdlrm
class-wp-block-parser-frame.php19160644editdlrm
class-wp-block-parser.php115320644editdlrm
class-wp-block-pattern-categories-registry.php53710644editdlrm
class-wp-block-patterns-registry.php100770644editdlrm
class-wp-block-styles-registry.php58830644editdlrm
class-wp-block-supports.php55190644editdlrm
class-wp-block-template.php19510644editdlrm
class-wp-block-type-registry.php50130644editdlrm
class-wp-block-type.php147430644editdlrm
class-wp-block.php84010644editdlrm
class-wp-classic-to-block-menu-converter.php40880644editdlrm
class-wp-comment-query.php478290644editdlrm
class-wp-comment.php93720644editdlrm
class-wp-customize-control.php258420644editdlrm
class-wp-customize-manager.php2022570644editdlrm
class-wp-customize-nav-menus.php575660644editdlrm
class-wp-customize-panel.php106700644editdlrm
class-wp-customize-section.php112440644editdlrm
class-wp-customize-setting.php298890644editdlrm
class-wp-customize-widgets.php716120644editdlrm
class-wp-date-query.php357190644editdlrm
class-wp-dependencies.php140620644editdlrm
class-wp-dependency.php26270644editdlrm
class-wp-duotone.php394430644editdlrm
class-wp-editor.php720840644editdlrm
class-wp-embed.php159940644editdlrm
class-wp-error.php75020644editdlrm
class-wp-fatal-error-handler.php78720644editdlrm
class-wp-feed-cache-transient.php25860644editdlrm
class-wp-feed-cache.php9690644editdlrm
class-wp-hook.php160000644editdlrm
class-wp-http-cookie.php73890644editdlrm
class-wp-http-curl.php125410644editdlrm
class-wp-http-encoding.php66890644editdlrm
class-wp-http-ixr-client.php35060644editdlrm
class-wp-http-proxy.php59800644editdlrm
class-wp-http-requests-hooks.php20220644editdlrm
class-wp-http-requests-response.php44000644editdlrm
class-wp-http-response.php29770644editdlrm
class-wp-http-streams.php168590644editdlrm
class-wp-http.php405850644editdlrm
class-wp-image-editor-gd.php175250644editdlrm
class-wp-image-editor-imagick.php376390644editdlrm
class-wp-image-editor.php175840644editdlrm
class-wp-list-util.php74430644editdlrm
class-wp-locale-switcher.php65610644editdlrm
class-wp-locale.php161150644editdlrm
class-wp-matchesmapregex.php18260644editdlrm
class-wp-meta-query.php305330644editdlrm
class-wp-metadata-lazyloader.php68330644editdlrm
class-wp-navigation-fallback.php92110644editdlrm
class-wp-network-query.php192910644editdlrm
class-wp-network.php121890644editdlrm
class-wp-object-cache.php176050644editdlrm
class-wp-oembed-controller.php68790644editdlrm
class-wp-oembed.php313940644editdlrm
class-wp-paused-extensions-storage.php50620644editdlrm
class-wp-post-type.php299780644editdlrm
class-wp-post.php64840644editdlrm
class-wp-query.php1515820644editdlrm
class-wp-recovery-mode-cookie-service.php68770644editdlrm
class-wp-recovery-mode-email-service.php111830644editdlrm
class-wp-recovery-mode-key-service.php45010644editdlrm
class-wp-recovery-mode-link-service.php34630644editdlrm
class-wp-recovery-mode.php114350644editdlrm
class-wp-rewrite.php634300644editdlrm
class-wp-role.php25230644editdlrm
class-wp-roles.php85800644editdlrm
class-wp-scripts.php286630644editdlrm
class-wp-session-tokens.php74510644editdlrm
class-wp-simplepie-file.php33770644editdlrm
class-wp-simplepie-sanitize-kses.php17700644editdlrm
class-wp-site-query.php310200644editdlrm
class-wp-site.php74540644editdlrm
class-wp-styles.php108980644editdlrm
class-wp-tax-query.php195450644editdlrm
class-wp-taxonomy.php185670644editdlrm
class-wp-term-query.php410150644editdlrm
class-wp-term.php52980644editdlrm
class-wp-text-diff-renderer-inline.php8290644editdlrm
class-wp-text-diff-renderer-table.php188070644editdlrm
class-wp-textdomain-registry.php59760644editdlrm
class-wp-theme-json-data.php15530644editdlrm
class-wp-theme-json-resolver.php246410644editdlrm
class-wp-theme-json-schema.php42230644editdlrm
class-wp-theme-json.php1295580644editdlrm
class-wp-theme.php642670644editdlrm
class-wp-user-meta-session-tokens.php29900644editdlrm
class-wp-user-query.php433910644editdlrm
class-wp-user-request.php22220644editdlrm
class-wp-user.php227620644editdlrm
class-wp-walker.php131660644editdlrm
class-wp-widget-factory.php33470644editdlrm
class-wp-widget.php183860644editdlrm
class-wp-xmlrpc-server.php2141400644editdlrm
class-wp.php261190644editdlrm
class-wpdb.php1194570644editdlrm
class.wp-dependencies.php3730644editdlrm
class.wp-scripts.php3430644editdlrm
class.wp-styles.php3380644editdlrm
comment-template.php1014320644editdlrm
comment.php1291120644editdlrm
compat.php152190644editdlrm
cron.php414730644editdlrm
date.php4000644editdlrm
default-constants.php111710644editdlrm
default-filters.php345060644editdlrm
default-widgets.php22220644editdlrm
deprecated.php1838090644editdlrm
embed-template.php3380644editdlrm
embed.php376590644editdlrm
error-protection.php41210644editdlrm
feed-atom-comments.php54510644editdlrm
feed-atom.php30480644editdlrm
feed-rdf.php26680644editdlrm
feed-rss.php11890644editdlrm
feed-rss2-comments.php40800644editdlrm
feed-rss2.php37990644editdlrm
feed.php230570644editdlrm
fonts.php23380644editdlrm
formatting.php3349910644editdlrm
functions.php2762850644editdlrm
functions.wp-scripts.php147590644editdlrm
functions.wp-styles.php85830644editdlrm
general-template.php1677240644editdlrm
global-styles-and-settings.php202050644editdlrm
http.php256240644editdlrm
https-detection.php56610644editdlrm
https-migration.php47410644editdlrm
kses.php720650644editdlrm
l10n.php627830644editdlrm
link-template.php1560750644editdlrm
load.php541290644editdlrm
locale.php1620644editdlrm
media-template.php618210644editdlrm
media.php2074260644editdlrm
meta.php640780644editdlrm
ms-blogs.php256280644editdlrm
ms-default-constants.php49000644editdlrm
ms-default-filters.php66360644editdlrm
ms-deprecated.php217580644editdlrm
ms-files.php27110644editdlrm
ms-functions.php912580644editdlrm
ms-load.php198700644editdlrm
ms-network.php37820644editdlrm
ms-settings.php41240644editdlrm
ms-site.php405020644editdlrm
nav-menu-template.php257850644editdlrm
nav-menu.php440520644editdlrm
option.php913400644editdlrm
pluggable-deprecated.php62630644editdlrm
pluggable.php1130210644editdlrm
plugin.php354650644editdlrm
post-formats.php71000644editdlrm
post-template.php667930644editdlrm
post-thumbnail-template.php103080644editdlrm
post.php2783200644editdlrm
query.php370350644editdlrm
registration-functions.php2000644editdlrm
registration.php2000644editdlrm
rest-api.php971440644editdlrm
revision.php309050644editdlrm
rewrite.php195140644editdlrm
robots-template.php51850644editdlrm
rss-functions.php2550644editdlrm
rss.php230150644editdlrm
script-loader.php1300790644editdlrm
session.php2580644editdlrm
shortcodes.php238560644editdlrm
sitemaps.php32380644editdlrm
spl-autoload-compat.php4410644editdlrm
style-engine.php72000644editdlrm
taxonomy.php1735280644editdlrm
template-canvas.php5440644editdlrm
template-loader.php33500644editdlrm
template.php235250644editdlrm
theme-i18n.json11510644editdlrm
theme-previews.php28260644editdlrm
theme-templates.php62230644editdlrm
theme.json73030644editdlrm
theme.php1312090644editdlrm
update.php368240644editdlrm
user.php1717980644editdlrm
vars.php62020644editdlrm
version.php9290644editdlrm
widgets.php698750644editdlrm
wp-db.php4450644editdlrm
wp-diff.php6470644editdlrm
Edit: /home/altere25/sportzsoft.altereddigital.com/wp-includes/kses.php (72065B)
* * @package External * @subpackage KSES */ /** * Specifies the default allowable HTML tags. * * Using `CUSTOM_TAGS` is not recommended and should be considered deprecated. The * {@see 'wp_kses_allowed_html'} filter is more powerful and supplies context. * * When using this constant, make sure to set all of these globals to arrays: * * - `$allowedposttags` * - `$allowedtags` * - `$allowedentitynames` * - `$allowedxmlentitynames` * * @see wp_kses_allowed_html() * @since 1.2.0 * * @var array[]|false Array of default allowable HTML tags, or false to use the defaults. */ if ( ! defined( 'CUSTOM_TAGS' ) ) { define( 'CUSTOM_TAGS', false ); } // Ensure that these variables are added to the global namespace // (e.g. if using namespaces / autoload in the current PHP environment). global $allowedposttags, $allowedtags, $allowedentitynames, $allowedxmlentitynames; if ( ! CUSTOM_TAGS ) { /** * KSES global for default allowable HTML tags. * * Can be overridden with the `CUSTOM_TAGS` constant. * * @var array[] $allowedposttags Array of default allowable HTML tags. * @since 2.0.0 */ $allowedposttags = array( 'address' => array(), 'a' => array( 'href' => true, 'rel' => true, 'rev' => true, 'name' => true, 'target' => true, 'download' => array( 'valueless' => 'y', ), ), 'abbr' => array(), 'acronym' => array(), 'area' => array( 'alt' => true, 'coords' => true, 'href' => true, 'nohref' => true, 'shape' => true, 'target' => true, ), 'article' => array( 'align' => true, ), 'aside' => array( 'align' => true, ), 'audio' => array( 'autoplay' => true, 'controls' => true, 'loop' => true, 'muted' => true, 'preload' => true, 'src' => true, ), 'b' => array(), 'bdo' => array(), 'big' => array(), 'blockquote' => array( 'cite' => true, ), 'br' => array(), 'button' => array( 'disabled' => true, 'name' => true, 'type' => true, 'value' => true, ), 'caption' => array( 'align' => true, ), 'cite' => array(), 'code' => array(), 'col' => array( 'align' => true, 'char' => true, 'charoff' => true, 'span' => true, 'valign' => true, 'width' => true, ), 'colgroup' => array( 'align' => true, 'char' => true, 'charoff' => true, 'span' => true, 'valign' => true, 'width' => true, ), 'del' => array( 'datetime' => true, ), 'dd' => array(), 'dfn' => array(), 'details' => array( 'align' => true, 'open' => true, ), 'div' => array( 'align' => true, ), 'dl' => array(), 'dt' => array(), 'em' => array(), 'fieldset' => array(), 'figure' => array( 'align' => true, ), 'figcaption' => array( 'align' => true, ), 'font' => array( 'color' => true, 'face' => true, 'size' => true, ), 'footer' => array( 'align' => true, ), 'h1' => array( 'align' => true, ), 'h2' => array( 'align' => true, ), 'h3' => array( 'align' => true, ), 'h4' => array( 'align' => true, ), 'h5' => array( 'align' => true, ), 'h6' => array( 'align' => true, ), 'header' => array( 'align' => true, ), 'hgroup' => array( 'align' => true, ), 'hr' => array( 'align' => true, 'noshade' => true, 'size' => true, 'width' => true, ), 'i' => array(), 'img' => array( 'alt' => true, 'align' => true, 'border' => true, 'height' => true, 'hspace' => true, 'loading' => true, 'longdesc' => true, 'vspace' => true, 'src' => true, 'usemap' => true, 'width' => true, ), 'ins' => array( 'datetime' => true, 'cite' => true, ), 'kbd' => array(), 'label' => array( 'for' => true, ), 'legend' => array( 'align' => true, ), 'li' => array( 'align' => true, 'value' => true, ), 'main' => array( 'align' => true, ), 'map' => array( 'name' => true, ), 'mark' => array(), 'menu' => array( 'type' => true, ), 'nav' => array( 'align' => true, ), 'object' => array( 'data' => array( 'required' => true, 'value_callback' => '_wp_kses_allow_pdf_objects', ), 'type' => array( 'required' => true, 'values' => array( 'application/pdf' ), ), ), 'p' => array( 'align' => true, ), 'pre' => array( 'width' => true, ), 'q' => array( 'cite' => true, ), 'rb' => array(), 'rp' => array(), 'rt' => array(), 'rtc' => array(), 'ruby' => array(), 's' => array(), 'samp' => array(), 'span' => array( 'align' => true, ), 'section' => array( 'align' => true, ), 'small' => array(), 'strike' => array(), 'strong' => array(), 'sub' => array(), 'summary' => array( 'align' => true, ), 'sup' => array(), 'table' => array( 'align' => true, 'bgcolor' => true, 'border' => true, 'cellpadding' => true, 'cellspacing' => true, 'rules' => true, 'summary' => true, 'width' => true, ), 'tbody' => array( 'align' => true, 'char' => true, 'charoff' => true, 'valign' => true, ), 'td' => array( 'abbr' => true, 'align' => true, 'axis' => true, 'bgcolor' => true, 'char' => true, 'charoff' => true, 'colspan' => true, 'headers' => true, 'height' => true, 'nowrap' => true, 'rowspan' => true, 'scope' => true, 'valign' => true, 'width' => true, ), 'textarea' => array( 'cols' => true, 'rows' => true, 'disabled' => true, 'name' => true, 'readonly' => true, ), 'tfoot' => array( 'align' => true, 'char' => true, 'charoff' => true, 'valign' => true, ), 'th' => array( 'abbr' => true, 'align' => true, 'axis' => true, 'bgcolor' => true, 'char' => true, 'charoff' => true, 'colspan' => true, 'headers' => true, 'height' => true, 'nowrap' => true, 'rowspan' => true, 'scope' => true, 'valign' => true, 'width' => true, ), 'thead' => array( 'align' => true, 'char' => true, 'charoff' => true, 'valign' => true, ), 'title' => array(), 'tr' => array( 'align' => true, 'bgcolor' => true, 'char' => true, 'charoff' => true, 'valign' => true, ), 'track' => array( 'default' => true, 'kind' => true, 'label' => true, 'src' => true, 'srclang' => true, ), 'tt' => array(), 'u' => array(), 'ul' => array( 'type' => true, ), 'ol' => array( 'start' => true, 'type' => true, 'reversed' => true, ), 'var' => array(), 'video' => array( 'autoplay' => true, 'controls' => true, 'height' => true, 'loop' => true, 'muted' => true, 'playsinline' => true, 'poster' => true, 'preload' => true, 'src' => true, 'width' => true, ), ); /** * @var array[] $allowedtags Array of KSES allowed HTML elements. * @since 1.0.0 */ $allowedtags = array( 'a' => array( 'href' => true, 'title' => true, ), 'abbr' => array( 'title' => true, ), 'acronym' => array( 'title' => true, ), 'b' => array(), 'blockquote' => array( 'cite' => true, ), 'cite' => array(), 'code' => array(), 'del' => array( 'datetime' => true, ), 'em' => array(), 'i' => array(), 'q' => array( 'cite' => true, ), 's' => array(), 'strike' => array(), 'strong' => array(), ); /** * @var string[] $allowedentitynames Array of KSES allowed HTML entity names. * @since 1.0.0 */ $allowedentitynames = array( 'nbsp', 'iexcl', 'cent', 'pound', 'curren', 'yen', 'brvbar', 'sect', 'uml', 'copy', 'ordf', 'laquo', 'not', 'shy', 'reg', 'macr', 'deg', 'plusmn', 'acute', 'micro', 'para', 'middot', 'cedil', 'ordm', 'raquo', 'iquest', 'Agrave', 'Aacute', 'Acirc', 'Atilde', 'Auml', 'Aring', 'AElig', 'Ccedil', 'Egrave', 'Eacute', 'Ecirc', 'Euml', 'Igrave', 'Iacute', 'Icirc', 'Iuml', 'ETH', 'Ntilde', 'Ograve', 'Oacute', 'Ocirc', 'Otilde', 'Ouml', 'times', 'Oslash', 'Ugrave', 'Uacute', 'Ucirc', 'Uuml', 'Yacute', 'THORN', 'szlig', 'agrave', 'aacute', 'acirc', 'atilde', 'auml', 'aring', 'aelig', 'ccedil', 'egrave', 'eacute', 'ecirc', 'euml', 'igrave', 'iacute', 'icirc', 'iuml', 'eth', 'ntilde', 'ograve', 'oacute', 'ocirc', 'otilde', 'ouml', 'divide', 'oslash', 'ugrave', 'uacute', 'ucirc', 'uuml', 'yacute', 'thorn', 'yuml', 'quot', 'amp', 'lt', 'gt', 'apos', 'OElig', 'oelig', 'Scaron', 'scaron', 'Yuml', 'circ', 'tilde', 'ensp', 'emsp', 'thinsp', 'zwnj', 'zwj', 'lrm', 'rlm', 'ndash', 'mdash', 'lsquo', 'rsquo', 'sbquo', 'ldquo', 'rdquo', 'bdquo', 'dagger', 'Dagger', 'permil', 'lsaquo', 'rsaquo', 'euro', 'fnof', 'Alpha', 'Beta', 'Gamma', 'Delta', 'Epsilon', 'Zeta', 'Eta', 'Theta', 'Iota', 'Kappa', 'Lambda', 'Mu', 'Nu', 'Xi', 'Omicron', 'Pi', 'Rho', 'Sigma', 'Tau', 'Upsilon', 'Phi', 'Chi', 'Psi', 'Omega', 'alpha', 'beta', 'gamma', 'delta', 'epsilon', 'zeta', 'eta', 'theta', 'iota', 'kappa', 'lambda', 'mu', 'nu', 'xi', 'omicron', 'pi', 'rho', 'sigmaf', 'sigma', 'tau', 'upsilon', 'phi', 'chi', 'psi', 'omega', 'thetasym', 'upsih', 'piv', 'bull', 'hellip', 'prime', 'Prime', 'oline', 'frasl', 'weierp', 'image', 'real', 'trade', 'alefsym', 'larr', 'uarr', 'rarr', 'darr', 'harr', 'crarr', 'lArr', 'uArr', 'rArr', 'dArr', 'hArr', 'forall', 'part', 'exist', 'empty', 'nabla', 'isin', 'notin', 'ni', 'prod', 'sum', 'minus', 'lowast', 'radic', 'prop', 'infin', 'ang', 'and', 'or', 'cap', 'cup', 'int', 'sim', 'cong', 'asymp', 'ne', 'equiv', 'le', 'ge', 'sub', 'sup', 'nsub', 'sube', 'supe', 'oplus', 'otimes', 'perp', 'sdot', 'lceil', 'rceil', 'lfloor', 'rfloor', 'lang', 'rang', 'loz', 'spades', 'clubs', 'hearts', 'diams', 'sup1', 'sup2', 'sup3', 'frac14', 'frac12', 'frac34', 'there4', ); /** * @var string[] $allowedxmlentitynames Array of KSES allowed XML entity names. * @since 5.5.0 */ $allowedxmlentitynames = array( 'amp', 'lt', 'gt', 'apos', 'quot', ); $allowedposttags = array_map( '_wp_add_global_attributes', $allowedposttags ); } else { $required_kses_globals = array( 'allowedposttags', 'allowedtags', 'allowedentitynames', 'allowedxmlentitynames', ); $missing_kses_globals = array(); foreach ( $required_kses_globals as $global_name ) { if ( ! isset( $GLOBALS[ $global_name ] ) || ! is_array( $GLOBALS[ $global_name ] ) ) { $missing_kses_globals[] = '$' . $global_name . ''; } } if ( $missing_kses_globals ) { _doing_it_wrong( 'wp_kses_allowed_html', sprintf( /* translators: 1: CUSTOM_TAGS, 2: Global variable names. */ __( 'When using the %1$s constant, make sure to set these globals to an array: %2$s.' ), 'CUSTOM_TAGS', implode( ', ', $missing_kses_globals ) ), '6.2.0' ); } $allowedtags = wp_kses_array_lc( $allowedtags ); $allowedposttags = wp_kses_array_lc( $allowedposttags ); } /** * Filters text content and strips out disallowed HTML. * * This function makes sure that only the allowed HTML element names, attribute * names, attribute values, and HTML entities will occur in the given text string. * * This function expects unslashed data. * * @see wp_kses_post() for specifically filtering post content and fields. * @see wp_allowed_protocols() for the default allowed protocols in link URLs. * * @since 1.0.0 * * @param string $content Text content to filter. * @param array[]|string $allowed_html An array of allowed HTML elements and attributes, * or a context name such as 'post'. See wp_kses_allowed_html() * for the list of accepted context names. * @param string[] $allowed_protocols Optional. Array of allowed URL protocols. * Defaults to the result of wp_allowed_protocols(). * @return string Filtered content containing only the allowed HTML. */ function wp_kses( $content, $allowed_html, $allowed_protocols = array() ) { if ( empty( $allowed_protocols ) ) { $allowed_protocols = wp_allowed_protocols(); } $content = wp_kses_no_null( $content, array( 'slash_zero' => 'keep' ) ); $content = wp_kses_normalize_entities( $content ); $content = wp_kses_hook( $content, $allowed_html, $allowed_protocols ); return wp_kses_split( $content, $allowed_html, $allowed_protocols ); } /** * Filters one HTML attribute and ensures its value is allowed. * * This function can escape data in some situations where `wp_kses()` must strip the whole attribute. * * @since 4.2.3 * * @param string $attr The 'whole' attribute, including name and value. * @param string $element The HTML element name to which the attribute belongs. * @return string Filtered attribute. */ function wp_kses_one_attr( $attr, $element ) { $uris = wp_kses_uri_attributes(); $allowed_html = wp_kses_allowed_html( 'post' ); $allowed_protocols = wp_allowed_protocols(); $attr = wp_kses_no_null( $attr, array( 'slash_zero' => 'keep' ) ); // Preserve leading and trailing whitespace. $matches = array(); preg_match( '/^\s*/', $attr, $matches ); $lead = $matches[0]; preg_match( '/\s*$/', $attr, $matches ); $trail = $matches[0]; if ( empty( $trail ) ) { $attr = substr( $attr, strlen( $lead ) ); } else { $attr = substr( $attr, strlen( $lead ), -strlen( $trail ) ); } // Parse attribute name and value from input. $split = preg_split( '/\s*=\s*/', $attr, 2 ); $name = $split[0]; if ( count( $split ) === 2 ) { $value = $split[1]; /* * Remove quotes surrounding $value. * Also guarantee correct quoting in $attr for this one attribute. */ if ( '' === $value ) { $quote = ''; } else { $quote = $value[0]; } if ( '"' === $quote || "'" === $quote ) { if ( ! str_ends_with( $value, $quote ) ) { return ''; } $value = substr( $value, 1, -1 ); } else { $quote = '"'; } // Sanitize quotes, angle braces, and entities. $value = esc_attr( $value ); // Sanitize URI values. if ( in_array( strtolower( $name ), $uris, true ) ) { $value = wp_kses_bad_protocol( $value, $allowed_protocols ); } $attr = "$name=$quote$value$quote"; $vless = 'n'; } else { $value = ''; $vless = 'y'; } // Sanitize attribute by name. wp_kses_attr_check( $name, $value, $attr, $vless, $element, $allowed_html ); // Restore whitespace. return $lead . $attr . $trail; } /** * Returns an array of allowed HTML tags and attributes for a given context. * * @since 3.5.0 * @since 5.0.1 `form` removed as allowable HTML tag. * * @global array $allowedposttags * @global array $allowedtags * @global array $allowedentitynames * * @param string|array $context The context for which to retrieve tags. Allowed values are 'post', * 'strip', 'data', 'entities', or the name of a field filter such as * 'pre_user_description', or an array of allowed HTML elements and attributes. * @return array Array of allowed HTML tags and their allowed attributes. */ function wp_kses_allowed_html( $context = '' ) { global $allowedposttags, $allowedtags, $allowedentitynames; if ( is_array( $context ) ) { // When `$context` is an array it's actually an array of allowed HTML elements and attributes. $html = $context; $context = 'explicit'; /** * Filters the HTML tags that are allowed for a given context. * * HTML tags and attribute names are case-insensitive in HTML but must be * added to the KSES allow list in lowercase. An item added to the allow list * in upper or mixed case will not recognized as permitted by KSES. * * @since 3.5.0 * * @param array[] $html Allowed HTML tags. * @param string $context Context name. */ return apply_filters( 'wp_kses_allowed_html', $html, $context ); } switch ( $context ) { case 'post': /** This filter is documented in wp-includes/kses.php */ $tags = apply_filters( 'wp_kses_allowed_html', $allowedposttags, $context ); // 5.0.1 removed the `
` tag, allow it if a filter is allowing it's sub-elements `` or `