[wp-trac] [WordPress Trac] #24564: wp_insert_post checks permissions of the current user, not the author

WordPress Trac noreply at wordpress.org
Wed Jun 12 03:18:36 UTC 2013


#24564: wp_insert_post checks permissions of the current user, not the author
--------------------------+------------------------------
 Reporter:  rmccue        |       Owner:
     Type:  defect (bug)  |      Status:  new
 Priority:  normal        |   Milestone:  Awaiting Review
Component:  Security      |     Version:
 Severity:  normal        |  Resolution:
 Keywords:                |
--------------------------+------------------------------

Comment (by rmccue):

 (From a quick look, this also applies to `wp_insert_attachment()` as
 well.)

--
Ticket URL: <http://core.trac.wordpress.org/ticket/24564#comment:1>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list