Wordpress 3.6
[autoinstalls/wordpress.git] / wp-admin / media-new.php
index c6a7ae141584e2df823d9e0ee64199c59a0975ef..e4288119573db1bfc087d9a323eff3b496809766 100644 (file)
@@ -68,7 +68,7 @@ if ( get_user_setting('uploader') || isset( $_GET['browser-uploader'] ) )
        <?php screen_icon(); ?>
        <h2><?php echo esc_html( $title ); ?></h2>
 
-       <form enctype="multipart/form-data" method="post" action="<?php echo admin_url('media-new.php'); ?>" class="<?php echo $form_class; ?>" id="file-form">
+       <form enctype="multipart/form-data" method="post" action="<?php echo admin_url('media-new.php'); ?>" class="<?php echo esc_attr( $form_class ); ?>" id="file-form">
 
        <?php media_upload_form(); ?>