diff --git a/wp-admin/edit-comments.php b/wp-admin/edit-comments.php index 6b4ff464d..6d074bef6 100644 --- a/wp-admin/edit-comments.php +++ b/wp-admin/edit-comments.php @@ -6,7 +6,7 @@ $parent_file = 'edit.php'; require_once('admin-header.php'); if (empty($_GET['mode'])) $mode = 'view'; -else $mode = $_GET['mode']; +else $mode = htmlspecialchars($_GET['mode']); ?>