Mobile nav dropdown aria-label can be corrupted by third-party wp_kses_allowed_html filters
I maintainer di solito rispondono entro 1 giorno
@Alexia-Soare ci sta già lavorando.
Dal 18/9/2026.
Valutazione
Questa issue non è ancora stata valutata.
Descrizione
The mobile sidebar dropdown toggle button's aria-label is built using wp_filter_nohtml_kses(), which is not resilient to third-party plugins that hook wp_kses_allowed_html incorrectly. When such a plugin adds allowed tags without respecting WordPress's reserved 'strip' context, the wrapper Neve adds around the menu title survives instead of being stripped, producing a corrupted, HTML-tag-filled aria-label on every dropdown menu item.
Steps to reproduce:
- Activate Neve, create a menu with at least one item that has children (e.g. "Shop" with a submenu), assign it to the Primary location.
- Install and activate the "Booster for WooCommerce" plugin (woocommerce-jetpack) — any recent version.
- View the mobile menu markup (view-source, or inspect the dropdown toggle button for "Shop").
Expected:
<button ... aria-label="Toggle Shop">
Actual:
<button ... aria-label="Toggle <span class=\"menu-item-title-wrap dd-title\">Shop</span>">
Root cause:
nav_walker.php:154:
$toggle_aria_label = __( 'Toggle', 'neve' ) . ' ' . wp_filter_nohtml_kses( $title );
$title at this point already contains our own ... wrapper (added a few lines earlier). We rely on wp_filter_nohtml_kses() to strip it back down to plain text before using it as an attribute value.
wp_filter_nohtml_kses() is a core WP function whose own docblock says "This function expects slashed data" — it's designed for sanitizing raw form/DB-bound input, not for stripping tags out of HTML we built ourselves. Internally it calls wp_kses( $data, 'strip' ), and that 'strip' context is passed through the public, pluggable wp_kses_allowed_html filter. Any plugin that hooks that filter and adds tags without checking $context === 'strip' will cause tags to survive a call that's supposed to guarantee zero tags. (Confirmed: Booster for WooCommerce's wcj_add_allowed_html() does exactly this.)
The value does get passed through esc_attr() before being output, so this isn't an XSS/broken-HTML issue — but it's a real accessibility regression (screen readers announce raw markup instead of the menu label) and is visible to anyone inspecting the DOM or running an accessibility audit.
Suggested fix:
Use wp_strip_all_tags() instead, since it does a plain string-based tag strip and never touches the wp_kses_allowed_html filter chain:
$toggle_aria_label = __( 'Toggle', 'neve' ) . ' ' . wp_strip_all_tags( $title );
This makes the dropdown toggle immune to this entire class of third-party filter conflicts, regardless of what any given plugin does wrong.
Severity: Low visual/security impact (escaped output), but a real accessibility bug and a support-burden source, since it presents as "menu looks broken" reports that are hard for less technical users/reporters to diagnose as a plugin conflict.
- Lingua principale
- PHP
- Stelle
- 307
- Fork
- 88
- Merge medio
- 1g 6h
- PR unite (30g)
- 10
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di Codeinwp/neve
-
bug-report bug-report-triage customer report regression
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
I maintainer di solito rispondono entro 1 giorno
-
feature-request-triage
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
I maintainer di solito rispondono entro 1 giorno
-
feature-request-triage
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
I maintainer di solito rispondono entro 1 giorno
-
Elementor single-color endpoint returns global_not_found for Neve palette colorsForse già presa @girishpanchal30 l’ha presa 3 giorni fa. Apertabug-report bug-report-triage customer report regression
Codeinwp/neve#4633 · 7 commenti · 1 assegnatario ·
I maintainer di solito rispondono entro 1 giorno
-
customer report feature-request-triage
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di Codeinwp/neve
Issue simili
-
sync-en
Difficoltà 1/5 1-3 ore Idoneità per principianti 88/100
I maintainer di solito rispondono entro 2 giorni
-
P2 testing
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
I maintainer di solito rispondono entro 1 giorno
-
1.severity: security
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
Automattic/static-site-importer#1879 ·
I maintainer di solito rispondono entro 1 giorno
-
bug Installation / Upgrade
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
I maintainer di solito rispondono entro 1 giorno