[wp-trac] [WordPress Trac] #36954: Cancelling an admin email address change on Multisite lacks a nonce

WordPress Trac noreply at wordpress.org
Thu Jul 7 17:10:11 UTC 2016


#36954: Cancelling an admin email address change on Multisite lacks a nonce
--------------------------------------+-------------------------
 Reporter:  johnbillion               |       Owner:  jeremyfelt
     Type:  defect (bug)              |      Status:  reviewing
 Priority:  lowest                    |   Milestone:  4.6
Component:  Administration            |     Version:
 Severity:  minor                     |  Resolution:
 Keywords:  good-first-bug has-patch  |     Focuses:  multisite
--------------------------------------+-------------------------

Comment (by jeremyfelt):

 @scottbasgaard Looks good! I made a small change in
 [attachment:36954.2.diff] so that the nonce is unique based on the site
 ID. Otherwise the same "cancel" URL would work on multiple sites.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/36954#comment:6>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list