WordPress自定义插件编辑器HTML标签字符转义异常求助
Let’s tackle this problem head-on—your HTML tags are getting encoded because of a small but critical mistake in how you’re passing content to the wp_editor function. Here’s what’s going wrong and how to fix it:
The Root Cause
In your email_field_body callback, you’re using esc_attr() to sanitize the saved editor content before passing it to wp_editor:
esc_attr( $this->options['email_field_body'])
esc_attr() is designed specifically for escaping text that will be used inside HTML attributes (like value=""). It converts special characters like < and > to their HTML entity equivalents (<, >), which breaks your email template’s HTML structure when loaded back into the editor.
The Solution
Replace esc_attr() with a sanitization function that preserves valid HTML tags. The best choice here is wp_kses_post()—it filters content to only allow safe HTML tags (the same ones permitted in WordPress post content), which is perfect for email templates.
Here’s your modified email_field_body function:
function email_field_body($args) { $content = isset( $this->options['email_field_body'] ) ? wp_kses_post( $this->options['email_field_body'] ) : ''; wp_editor( $content, 'email_field_body', array( 'textarea_name' => "registration_email[email_field_body]" ) ); }
Bonus: Ensure Proper Saving
To make sure the content stays intact when saved, you also need to use wp_kses_post() in your settings save logic. If you haven’t already, update your save handler to look like this:
// Inside your settings save method if (isset($_POST['registration_email']) && current_user_can('manage_options')) { $sanitized_options = $this->options; // Preserve valid HTML while sanitizing $sanitized_options['email_field_body'] = wp_kses_post($_POST['registration_email']['email_field_body']); update_option('registration_email', $sanitized_options); }
Why This Works
wp_kses_post()keeps safe HTML tags (like<p>,<strong>, or<a>) intact while stripping out malicious code, so your email template’s structure stays correct.- Unlike
esc_attr(), it doesn’t encode standard HTML characters—your<and>tags remain as-is, and dynamic variables like[USER_NAME]and[USER_PWD]will populate without issues.
Test this out, and your email template should load and render HTML correctly now—no more entity-encoded tags messing up your layout!
内容的提问来源于stack exchange,提问作者Arghya

