From b06c392ab349ce20d846fd9d50180595d2b85ff4 Mon Sep 17 00:00:00 2001 From: Jeff Stieler Date: Fri, 24 May 2019 13:05:12 -0400 Subject: [PATCH] Prevent double escaping of note action URLs. --- .../woocommerce-admin/includes/notes/class-wc-admin-note.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/plugins/woocommerce-admin/includes/notes/class-wc-admin-note.php b/plugins/woocommerce-admin/includes/notes/class-wc-admin-note.php index 0a3d5f5c88f..b13d0de7739 100644 --- a/plugins/woocommerce-admin/includes/notes/class-wc-admin-note.php +++ b/plugins/woocommerce-admin/includes/notes/class-wc-admin-note.php @@ -485,7 +485,7 @@ class WC_Admin_Note extends WC_Data { public function add_action( $name, $label, $url = '', $status = self::E_WC_ADMIN_NOTE_ACTIONED, $primary = false ) { $name = wc_clean( $name ); $label = wc_clean( $label ); - $query = esc_url( $url ); + $query = esc_url_raw( $url ); $status = wc_clean( $status ); $primary = (bool) $primary;