Skip to:
Content

BuddyPress.org

Ticket #7317: 7317.diff

File 7317.diff, 700 bytes (added by boonebgorges, 3 years ago)
  • src/bp-xprofile/bp-xprofile-functions.php

    diff --git src/bp-xprofile/bp-xprofile-functions.php src/bp-xprofile/bp-xprofile-functions.php
    index 0fdd7ad..93218a1 100644
    function bp_xprofile_fullname_field_id() { 
    10631063                global $wpdb;
    10641064
    10651065                $bp = buddypress();
    1066                 $id = $wpdb->get_var( $wpdb->prepare( "SELECT id FROM {$bp->profile->table_name_fields} WHERE name = %s", bp_xprofile_fullname_field_name() ) );
     1066                $id = $wpdb->get_var( $wpdb->prepare( "SELECT id FROM {$bp->profile->table_name_fields} WHERE name = %s", addslashes( bp_xprofile_fullname_field_name() ) ) );
    10671067
    10681068                wp_cache_set( 'fullname_field_id', $id, 'bp_xprofile' );
    10691069        }