From 4b812eb11f0deb1913befd33857b3c03059ae666 Mon Sep 17 00:00:00 2001 From: ryan Date: Fri, 25 Jan 2008 02:21:59 +0000 Subject: [PATCH] Unescape user data before sending to wpdb::update() and wpdb::insert(), which expect unescaped data. git-svn-id: http://svn.automattic.com/wordpress/trunk@6656 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-includes/registration.php | 1 + 1 file changed, 1 insertion(+) diff --git a/wp-includes/registration.php b/wp-includes/registration.php index 48fb2b1c8..343a887ef 100644 --- a/wp-includes/registration.php +++ b/wp-includes/registration.php @@ -158,6 +158,7 @@ function wp_insert_user($userdata) { $user_registered = gmdate('Y-m-d H:i:s'); $data = compact( 'user_pass', 'user_email', 'user_url', 'user_nicename', 'display_name', 'user_registered' ); + $data = stripslashes_deep( $data ); if ( $update ) { $wpdb->update( $wpdb->users, $data, compact( 'ID' ) );