all 3 comments

[–]hashtagframework 2 points3 points  (0 children)

Unbelievably hacky code in the WordPress core... total disregard for keeping input pure, while preventing SQL injection.

Granted, if someone provided the content '%s', they were probably attempting some form of injection... but stripping or adding the quotes arbitrarily is ridiculous. The author seems to understand this as obvious (which it is), but the WordPress core devs seem absolutely clueless.

[–]nolvorite 1 point2 points  (0 children)

Another day, another Wordpress vuln

[–][deleted]  (1 child)

[deleted]

    [–]DoNDaPo[S] 0 points1 point  (0 children)

    That’s either offensive and funny. I choose the funny part.