for form filters
authorSteve Sutton <steve@gaslightmedia.com>
Thu, 16 Oct 2014 16:42:09 +0000 (12:42 -0400)
committerSteve Sutton <steve@gaslightmedia.com>
Thu, 16 Oct 2014 16:42:09 +0000 (12:42 -0400)
GlmQuickSite.php

index 3c4d0e6..41dd106 100644 (file)
@@ -233,7 +233,8 @@ function glmQuickSiteRenderText($fieldName) {
         $options = get_option( 'glmQuickSite_settings' );
     }
 ?>
-    <input type='text' name='glmQuickSite_settings[<?php echo $fieldName;?>]' value='<?php echo $options[$fieldName]; ?>'>
+    <input type="text" name="glmQuickSite_settings[<?php echo $fieldName;?>]"
+           value="<?php echo strp_replace('"', '&quote;', $options[$fieldName]); ?>">
 <?php
 }
 
@@ -241,7 +242,7 @@ function glmQuickSiteRenderTextArea($fieldName) {
     static $options;
     $options = get_option( 'glmQuickSite_settings' );
 ?>
-    <textarea cols='40' rows='5' name='glmQuickSite_settings[<?php echo $fieldName;?>]'><?php echo $options[$fieldName]; ?></textarea>
+    <textarea cols="40" rows="5" name="glmQuickSite_settings[<?php echo $fieldName;?>]"><?php echo htmlspecialchars($options[$fieldName]); ?></textarea>
 <?php
 }