|
#16822
|
FORCE_SSL_LOGIN causes wp-login.php to have an incorrect https link
|
jakub.tyrcha*
|
Security
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
09/10/11
|
|
#10267
|
Login form SSL is confusing
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
11/24/09
|
|
#4137
|
Pingback Denial of Service possibility
|
|
Security
|
low
|
normal
|
Awaiting Review
|
defect (bug)
|
|
02/01/13
|
|
#11813
|
Post password stored as plaintext
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
09/17/12
|
|
#10268
|
Profile and Edit user pages should be secure too
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
11/13/10
|
|
#16483
|
Visibility: password-protected exposes multiple pages
|
|
Security
|
normal
|
minor
|
Future Release
|
defect (bug)
|
dev-feedback
|
03/18/13
|
|
#13051
|
admin_url() and site_url() shouldn't need esc_url()
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
11/13/10
|
|
#12402
|
make addslashes_gpc() use addslashes() fix to use real_escape, rather than addslashes
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
11/13/10
|
|
#9207
|
redirect_to wp-admin Should Force SSL If FORCE_SSL_ADMIN is enabled
|
hakre*
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
reporter-feedback
|
04/06/13
|
|
#11623
|
review options list and update sanitize_option()
|
dd32*
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
early
|
11/13/10
|
|
#10551
|
wp_die() triggers block when using ModSecurity Core Rules
|
westi*
|
Security
|
low
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
03/22/11
|
|
#14148
|
wp_get_attachment_url() is not url encoding
|
|
Security
|
normal
|
major
|
Future Release
|
defect (bug)
|
has-patch
|
12/20/10
|
|
#19415
|
wp_nav_menu showing private/conctepts posts without rights
|
|
Security
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
|
11/01/12
|
|
#14803
|
Admins should be warned if authentication keys and salts have the default phrase
|
|
Security
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
08/06/12
|
|
#21022
|
Allow bcrypt to be enabled via filter for pass hashing
|
|
Security
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
03/05/13
|
|
#15277
|
FORCE_SSL_LOGIN or _ADMIN go to death loops when using an load-balancer
|
|
Security
|
normal
|
normal
|
Future Release
|
enhancement
|
|
12/29/10
|
|
#10151
|
HTML5 <video> elements stripped in kses.php
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
01/05/12
|
|
#10741
|
Include user's IP address in the lost password message
|
ryan
|
Security
|
normal
|
minor
|
Future Release
|
enhancement
|
has-patch
|
11/20/09
|
|
#24063
|
Introduce some more _doing_it_wrong() calls in nonce functions
|
|
Security
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
has-patch
|
04/12/13
|
|
#20779
|
Recommend a user updates keys/salts in maint/repair.php
|
|
Security
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
06/27/12
|
|
#20276
|
Tie nonces to the current session
|
|
Security
|
normal
|
normal
|
Future Release
|
enhancement
|
|
01/28/13
|
|
#20060
|
wp_redirect() doesn't exit
|
|
Security
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
02/27/12
|
|
#20140
|
Ask old password to change user password
|
tman4506*
|
Security
|
normal
|
normal
|
Awaiting Review
|
feature request
|
dev-feedback
|
08/26/12
|
|
#10237
|
Implement Content Security Policy to prevent XSS
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
feature request
|
|
06/20/12
|
|
#10850
|
Make register_setting available on the front-end
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
feature request
|
|
09/25/09
|
|
#21737
|
Users should have to jump through hoops to set passwords of their choosing, and we should guard better against weak passwords
|
westi*
|
Security
|
normal
|
normal
|
Awaiting Review
|
feature request
|
|
04/18/13
|
|
#21924
|
add action / filter to wp-login.php so we can replace WordPress login and force using 3rd party login
|
|
Security
|
normal
|
normal
|
Awaiting Review
|
feature request
|
|
09/19/12
|
|
#17227
|
wp should work around bug in move_uploaded_file for tighter security
|
|
Security
|
normal
|
normal
|
Awaiting Review
|
feature request
|
|
11/17/11
|
|
#23798
|
Audio Shortcode: Fallback link gets cropped by fixed-height container.
|
|
Shortcodes
|
normal
|
normal
|
3.6
|
defect (bug)
|
has-patch
|
04/15/13
|
|
#23801
|
Audio Shortcode: MP3s Display above plain text.
|
|
Shortcodes
|
normal
|
normal
|
3.6
|
defect (bug)
|
|
05/16/13
|
|
#15694
|
Caption Shortcode I/O Intolerant of "]" Char
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
02/27/12
|
|
#14380
|
Caption shortcode inserts inline style forcing width of containing div
|
nacin*
|
Shortcodes
|
normal
|
minor
|
Future Release
|
defect (bug)
|
dev-feedback
|
01/31/13
|
|
#19639
|
Enhancement: request: filter support before shortcodes are parsed or convert " into "
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
12/22/11
|
|
#19927
|
Improve support escaping a shortcode tag
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
01/30/12
|
|
#7045
|
No name shortcode atts
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
11/01/12
|
|
#23694
|
Shortcode attributes mess up html strings
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
03/07/13
|
|
#23517
|
Shortcode: if last parameter ends with '/', it is mistaken for self-closing shortcode closure
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
02/19/13
|
|
#12061
|
Treatment of shortcodes by wpautop is incomplete
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
01/19/13
|
|
#18776
|
balanceTags should ignore shortcodes & their content
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
04/27/12
|
|
#21158
|
different result when shortcode atribute without value
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
07/04/12
|
|
#23307
|
shortcode_parse_atts may return empty string
|
|
Shortcodes
|
normal
|
minor
|
Awaiting Review
|
defect (bug)
|
has-patch
|
01/28/13
|
|
#22272
|
shortcode_unautop() Doesn't Account for Opening/Closing Shortcode tags each Being on Their Own Line
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
10/24/12
|
|
#22127
|
strange behaviour with shortcode with the_content filter
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
10/08/12
|
|
#24085
|
wpautop filter and shortcodes
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
05/17/13
|
|
#12368
|
Allow setting limit in do_shortcode()
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
enhancement
|
reporter-feedback
|
03/08/10
|
|
#18558
|
Handling of dormant shortcodes is inelegant
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
has-patch
|
09/10/11
|
|
#23855
|
Leave Shortcode functions early, if there's no Shortcode delimiter
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
has-patch
|
04/04/13
|
|
#14481
|
Shortcode Enhancements
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
enhancement
|
needs-unit-tests
|
10/31/10
|
|
#23786
|
Shortcodes working inside HTML and PHP comments
|
|
Shortcodes
|
normal
|
minor
|
Awaiting Review
|
enhancement
|
|
03/15/13
|
|
#10702
|
Support for complex nested shorttags
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
11/06/12
|
|
#19968
|
Use named regular expression groups to simplify shortcodes code
|
|
Shortcodes
|
normal
|
minor
|
Awaiting Review
|
enhancement
|
|
02/06/12
|
|
#20659
|
Document available shortcodes in eg. new post page
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
feature request
|
|
05/22/12
|
|
#12982
|
Shortcodes don't allow shortcodes in attributes
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
feature request
|
needs-unit-tests
|
04/15/10
|
|
#19044
|
$depth in start_el Walker_Category has null value
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
reporter-feedback
|
10/28/11
|
|
#24385
|
Adding and Deleting Custom Taxonomies not Working
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
05/22/13
|
|
#8119
|
Attempts to edit deleted categories are not properly handled
|
westi
|
Taxonomy
|
normal
|
minor
|
Future Release
|
defect (bug)
|
has-patch
|
11/19/11
|
|
#23668
|
Check for empty slug input in register_taxonomy
|
|
Taxonomy
|
normal
|
normal
|
3.6
|
defect (bug)
|
dev-feedback
|
04/09/13
|
|
#13606
|
Comma's in taxonomy term names make them unpickable
|
|
Taxonomy
|
normal
|
major
|
Future Release
|
defect (bug)
|
|
11/13/10
|
|
#18553
|
Counting of categories doesn't work without refreshing?
|
|
Taxonomy
|
normal
|
minor
|
Awaiting Review
|
defect (bug)
|
|
09/03/11
|
|
#14073
|
Custom Taxonomies - Post Count wrong
|
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
reporter-feedback
|
11/13/10
|
|
#14370
|
Custom Taxonomies tagging Attachments
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
08/30/12
|
|
#15264
|
Deleting a term shared across taxonomies deletes all associated nav menus.
|
garyc40
|
Taxonomy
|
normal
|
major
|
Future Release
|
defect (bug)
|
has-patch
|
05/21/13
|
|
#21842
|
Diffrerent Custom Taxonomy Unable to Have Same Term Name in Version 3.4.2
|
oneTarek
|
Taxonomy
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
reporter-feedback
|
09/14/12
|
|
#11156
|
Duplicate tag created if tag name contains ampersand
|
filosofo
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
11/13/10
|
|
#20850
|
Duplicate term insertion allowed after insertion with case differences
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
06/08/12
|
|
#16797
|
Edit Tags admin + custom post type + custom taxonomy
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
03/08/11
|
|
#12729
|
Fix [6326] - wp_unique_term_slug() when changing the parent
|
ryan
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
11/25/12
|
|
#23069
|
For plugins that create custom taxonomies, wp_delete_term does not work during plugin uninstall.
|
|
Taxonomy
|
normal
|
trivial
|
Awaiting Review
|
defect (bug)
|
|
01/02/13
|
|
#14093
|
Malformed category hidden from edit-tags, but shows in meta box
|
|
Taxonomy
|
low
|
normal
|
Future Release
|
defect (bug)
|
|
01/13/11
|
|
#19112
|
Minor fix in category-template.php
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
11/16/11
|
|
#16101
|
Numeric term fields are strings
|
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
02/13/13
|
|
#19205
|
Orphaned categories can be created by accident
|
|
Taxonomy
|
normal
|
minor
|
Awaiting Review
|
defect (bug)
|
|
11/19/11
|
|
#9875
|
Postcount not set for parent in category dropdown.
|
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
07/01/10
|
|
#19492
|
Problems with using wp_insert_term together with switch_to_blog
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
12/09/11
|
|
#5358
|
Queried object on multiple tag query holds only first tag
|
ryan
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
01/28/13
|
|
#24376
|
Sharing Custom Taxonomies with built-in Post Types
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
05/21/13
|
|
#22511
|
Taxonomy manage screen checks for manage_terms and edit_terms, instead of just manage_terms.
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
11/20/12
|
|
#15741
|
Taxonomy: Duplicate term slug error message refers to the name
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
02/25/11
|
|
#17689
|
Terms should not be sanitized inside term_exists()
|
|
Taxonomy
|
normal
|
normal
|
3.6
|
defect (bug)
|
needs-unit-tests
|
05/05/13
|
|
#5809
|
Updating a term in one taxonomy affects the term in every taxonomy
|
garyc40
|
Taxonomy
|
high
|
major
|
Future Release
|
defect (bug)
|
has-patch
|
05/15/13
|
|
#19590
|
Warnings when unregistering core taxonomies and post types
|
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
12/20/12
|
|
#20635
|
_pad_term_count get's stuck if there is a loop in the hierarchy
|
westi*
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
12/06/12
|
|
#18828
|
function wp_get_object_terms() passes sql data into `wp_get_object_terms` filter for $taxonomies
|
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
11/15/11
|
|
#17807
|
get_adjacent_post() doesn't work with custom taxonomies
|
nacin
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
05/15/13
|
|
#21200
|
get_all_category_ids() only used by a deprecated function
|
|
Taxonomy
|
normal
|
minor
|
Awaiting Review
|
defect (bug)
|
|
09/08/12
|
|
#24354
|
get_cat_id() fails with category names containing ampersand
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
05/17/13
|
|
#8722
|
get_categories allows custom taxos, get_category doesn't
|
ryan
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
08/15/10
|
|
#16310
|
get_taxonomy_labels() and _get_custom_object_labels() fail if $object->taxonomy is not array
|
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
05/13/12
|
|
#14399
|
get_term_children doesn't call clean_term_cache() if necessary
|
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
01/15/11
|
|
#17652
|
get_term_link doesn't accept $term->term_id without explicit casting as numeric
|
|
Taxonomy
|
normal
|
minor
|
Awaiting Review
|
defect (bug)
|
|
05/01/13
|
|
#17365
|
get_terms doesn't return terms with no posts if you specify a parent
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
05/10/11
|
|
#23506
|
get_terms() assumes its taxonomies argument is a numeric array with a 0 key
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
02/19/13
|
|
#16240
|
hide_empty doesn't work in get_terms() when hierarchical isn't set to false
|
markjaquith
|
Taxonomy
|
high
|
major
|
Future Release
|
defect (bug)
|
close
|
09/13/12
|
|
#12981
|
odd behavior of exclude_tree parameter in wp_list_categories()
|
tott
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
11/13/10
|
|
#7559
|
strip_tags() breaks category names with left angle brackets
|
ryan
|
Taxonomy
|
normal
|
minor
|
Future Release
|
defect (bug)
|
|
07/01/10
|
|
#21606
|
term_exists returns 0 and null
|
barrykooij
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
11/06/12
|
|
#18625
|
term_exists() doesn't make a difference between z and ẓ
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
09/09/11
|
|
#18609
|
term_id collisions possible with InnoDB tables and global_terms_enabled
|
|
Taxonomy
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
|
10/19/11
|
|
#14343
|
user_can_access_admin_page not recognising taxonomies
|
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
12/07/10
|
|
#24073
|
wp_ajax_ajax_tag_search
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
reporter-feedback
|
04/14/13
|