diff --git a/src/js/_enqueues/vendor/plupload/wp-plupload.js b/src/js/_enqueues/vendor/plupload/wp-plupload.js
index c0eb570657bf4..1ba0b2cd41bdf 100644
--- a/src/js/_enqueues/vendor/plupload/wp-plupload.js
+++ b/src/js/_enqueues/vendor/plupload/wp-plupload.js
@@ -481,7 +481,10 @@ window.wp = window.wp || {};
'SECURITY_ERROR': pluploadL10n.security_error,
'FILE_SIZE_ERROR': function( file ) {
- return pluploadL10n.file_exceeds_size_limit.replace( '%s', file.name );
+ return pluploadL10n.file_exceeds_size_limit.replace(
+ '%s',
+ '' + _.escape(file.name) + ''
+ );
},
'HTTP_ERROR': function( file ) {
diff --git a/src/wp-includes/media-template.php b/src/wp-includes/media-template.php
index bc887bafd1197..aeb8314d3a8dd 100644
--- a/src/wp-includes/media-template.php
+++ b/src/wp-includes/media-template.php
@@ -362,8 +362,7 @@ function wp_print_media_templates() {