SOLVED: Component names are not escaped in the Editor

We just noticed part of a component label was missing, and it seems like <> are not escaped for component names, allowing for some element injection into the editor’s UI.

Hi Milo,
Thanks so much for your report!

I reproduced the issue and added it to our bug tracker.
We’ll update this thread once it’s fixed.

Best regards,
timmse

1 Like

We’ve addressed this in Bricks 2.3.7, now available as a one-click update in your WordPress Dashboard.

Please read the changelog entry before updating, and let us know if you experience any issues.