[wp-trac] [WordPress Trac] #15326: Always check capabilites in admin pages

WordPress Trac wp-trac at lists.automattic.com
Thu Dec 16 08:43:24 UTC 2010


#15326: Always check capabilites in admin pages
-------------------------+--------------------
 Reporter:  westi        |       Owner:  westi
     Type:  enhancement  |      Status:  new
 Priority:  high         |   Milestone:  3.1
Component:  Security     |     Version:  3.1
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+--------------------

Comment (by nacin):

 (In [16990]) Remove check_permissions() calls outside of AJAX context.
 Also only check for switch_themes in check_permissions() for the themes
 table. see #15326.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/15326#comment:9>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list