From e9b0e8284b0e791481db1c8ce65bd1f7d8c8bec6 Mon Sep 17 00:00:00 2001 From: markjaquith Date: Wed, 1 Aug 2007 17:20:01 +0000 Subject: [PATCH] attribute_escape() in upload form action. Props Nazgul. fixes #4689 for trunk git-svn-id: http://svn.automattic.com/wordpress/trunk@5827 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-admin/includes/upload.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/wp-admin/includes/upload.php b/wp-admin/includes/upload.php index b09ff2fdff..3f472e0287 100644 --- a/wp-admin/includes/upload.php +++ b/wp-admin/includes/upload.php @@ -105,8 +105,9 @@ function wp_upload_form() { $id = get_the_ID(); global $post_id, $tab, $style; $enctype = $id ? '' : ' enctype="multipart/form-data"'; + $post_id = (int) $post_id; ?> - id="upload-file" method="post" action=""> + id="upload-file" method="post" action="">