WordPress登录时出现mysqli_real_escape_string参数类型错误求助
Hey there, let's tackle this frustrating error you're running into. The warning mysqli_real_escape_string() expects parameter 2 to be string, object given in /public_html/wp-includes/wp-db.php line 1105 boils down to one core issue: somewhere in your site's code, an object is being passed to a function that expects a plain string.
Why This Happens
The _real_escape() method in WordPress's database class is built to sanitize string inputs for safe database queries. When something—like a buggy plugin, theme, or custom code—accidentally feeds it an object (say, a WP_Post instance or a custom class) instead of a string, PHP throws this warning. Common triggers include:
- A recent plugin/theme update that introduced a code regression
- Custom code you added that mishandles variable types when interacting with the database
- A compatibility conflict between your current WordPress version and a third-party tool
Step-by-Step Fixes
1. Isolate the Culprit with Plugin/Theme Testing
Start with the classic WordPress troubleshooting workflow to narrow down the source:
- Disable all plugins: Head to your WP Admin → Plugins → Select all → Bulk Actions → Deactivate. If the error disappears, reactivate plugins one by one until the warning returns—you've found the problematic plugin. Update it, reach out to its developer, or replace it if needed.
- Switch to a default theme: Activate a stock theme like Twenty Twenty-Four. If the error goes away, your current theme has a bug in its database handling code. Check the theme's functions or template files for calls to
$wpdbmethods where an object is being passed instead of a string.
2. Audit Custom Code
If you've added custom code (in functions.php, a child theme, or a custom plugin), hunt for any database-related calls:
- Look for uses of
$wpdb->_real_escape(),mysqli_real_escape_string(), or$wpdb->prepare(). - Double-check that you're passing string values, not objects. For example, if working with a post, use
$post->post_titleinstead of the full$postobject.
3. Temporary Quick Fix (Not Long-Term)
If you need to get your site working immediately while tracking down the root cause, you can add a type check to the _real_escape() function in wp-includes/wp-db.php. Note: Core WordPress updates will overwrite this change, so use it only as a stopgap.
Modify the function like this:
function _real_escape( $string ) { // Add this check to convert non-string inputs to strings if ( is_object( $string ) || ! is_string( $string ) ) { $string = strval( $string ); } if ( $this->dbh ) { if ( $this->use_mysqli ) { $escaped = mysqli_real_escape_string( $this->dbh, $string ); } else { $escaped = mysql_real_escape_string( $string, $this->dbh ); } return $escaped; } return addslashes( $string ); }
4. Update Everything
Make sure your WordPress core, plugins, and theme are all running the latest versions. Many times, these types of type-mismatch bugs are fixed in official updates.
Final Note
The key to a permanent fix is finding exactly where the object is being passed instead of a string. The plugin/theme isolation step is usually the fastest way to pinpoint the issue.
内容的提问来源于stack exchange,提问作者Khirad Zahra

