@@ -1193,6 +1193,25 @@ function (response) {
1193
1193
*/
1194
1194
function get_support () {
1195
1195
1196
+ $ allowed_html = array (
1197
+ 'div ' => array ('class ' => array (), 'id ' => array ()),
1198
+ 'button ' => array ('type ' => array (), 'class ' => array (), 'aria-expanded ' => array ()),
1199
+ 'span ' => array ('class ' => array (), 'aria-hidden ' => array ()),
1200
+ 'h3 ' => array ('class ' => array ()),
1201
+ 'form ' => array ('name ' => array (), 'id ' => array (), 'action ' => array (), 'method ' => array (), 'onsubmit ' => array ()),
1202
+ 'input ' => array ('type ' => array (), 'name ' => array (), 'class ' => array (), 'value ' => array (), 'required ' => array (), 'id ' => array ()),
1203
+ 'label ' => array ('for ' => array (), 'strong ' => array ()),
1204
+ 'strong ' => array (),
1205
+ 'p ' => array (),
1206
+ 'table ' => array ('class ' => array ()),
1207
+ 'tr ' => array (),
1208
+ 'td ' => array ('class ' => array ()),
1209
+ 'select ' => array ('class ' => array (), 'name ' => array ()),
1210
+ 'option ' => array ('value ' => array ()),
1211
+ 'textarea ' => array ('class ' => array (), 'name ' => array (), 'required ' => array (), 'rows ' => array (), 'cols ' => array ()),
1212
+ 'ul ' => array ('class ' => array ()),
1213
+ );
1214
+
1196
1215
$ html = '
1197
1216
<div class="postbox bsf-contact closed">
1198
1217
<button type="button" class="handlediv" aria-expanded="false"><span class="screen-reader-text">Toggle panel: Frontend Options</span><span class="toggle-indicator" aria-hidden="true"></span></button>
@@ -1232,6 +1251,6 @@ function get_support() {
1232
1251
</div>
1233
1252
</div>
1234
1253
' ;
1235
- return $ html ;
1254
+ return wp_kses ( $ html, $ allowed_html ) ;
1236
1255
}
1237
1256
?>
0 commit comments