Plugin Directory

Changeset 1122852


Ignore:
Timestamp:
03/28/2015 08:48:35 PM (11 years ago)
Author:
pathawks
Message:

We had better escape our queries

File:
1 edited

Legend:

Unmodified
Added
Removed
  • dirtysuds-category-thumbnail/trunk/thumb.php

    r1119043 r1122852  
    4141
    4242    $embed = '';
    43     $posts = get_posts('cat='.$id.'&post_type='.$post_type.'&showposts=1&meta_key=_thumbnail_id');
     43    $q = $wpdb->prepare(
     44        'cat=%s&post_type=%s&showposts=1&meta_key=_thumbnail_id',
     45        $id,
     46        $post_type
     47    );
     48    $posts = get_posts( $q );
    4449    if( isset( $posts[0] ) ) {
    4550        $embed = get_the_post_thumbnail($posts[0]->ID, $size);
Note: See TracChangeset for help on using the changeset viewer.