[wp-trac] [WordPress Trac] #13000: delete_themes and delete_plugins caps do not obey DISALLOW_FILE_EDIT

WordPress Trac wp-trac at lists.automattic.com
Wed Apr 14 17:01:02 UTC 2010


#13000: delete_themes and delete_plugins caps do not obey DISALLOW_FILE_EDIT
--------------------------+-------------------------------------------------
 Reporter:  ryan          |       Owner:  ryan
     Type:  defect (bug)  |      Status:  new 
 Priority:  normal        |   Milestone:  3.0 
Component:  Security      |     Version:      
 Severity:  normal        |    Keywords:      
--------------------------+-------------------------------------------------

Comment(by ryan):

 Such sites would probably need to disallow anything that touches files.
 Plugin/theme update, delete, install, and edit as well as core upgrades.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/13000#comment:3>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list