diff options
Diffstat (limited to 'wp-includes/pluggable.php')
| -rw-r--r-- | wp-includes/pluggable.php | 5 |
1 files changed, 4 insertions, 1 deletions
diff --git a/wp-includes/pluggable.php b/wp-includes/pluggable.php index 9c2440f..ab054bf 100644 --- a/wp-includes/pluggable.php +++ b/wp-includes/pluggable.php @@ -266,7 +266,10 @@ if ( !function_exists('wp_redirect') ) : function wp_redirect($location) { global $is_IIS; - $location = str_replace( array("\n", "\r"), '', $location); + $location = preg_replace('|[^a-z0-9-~+_.?#=&;,/:%]|i', '', $location); + + $strip = array('%0d', '%0a'); + $location = str_replace($strip, '', $location); if ($is_IIS) header("Refresh: 0;url=$location"); |
