|
#20745
|
Hard-code less capability types
|
|
Role/Capability
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
05/25/12
|
|
#16808
|
Insufficient permissions for custom post type management and custom role/caps
|
|
Role/Capability
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
03/09/11
|
|
#21788
|
Relocate revoke_super_admin() and grant_super_admin() to capabilities.php
|
|
Role/Capability
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
09/16/12
|
|
#16719
|
Remove vestige add_users capability
|
|
Role/Capability
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
10/25/12
|
|
#19747
|
Roles add_cap should call update_user_level_from_caps()
|
|
Role/Capability
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
12/12/12
|
|
#24153
|
Sticky flag gets unset if author doesn't have publish_posts permission
|
|
Role/Capability
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
|
04/23/13
|
|
#16451
|
WP_Roles and capabilities
|
|
Role/Capability
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
02/03/11
|
|
#23746
|
add_role require string does not check for empty string
|
|
Role/Capability
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
03/13/13
|
|
#21526
|
get_post_type_capabilities() assumes $args->capabilities is an array
|
|
Role/Capability
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
08/09/12
|
|
#16841
|
manually created user roles not showing in author dropdown irregardless of assigned capabilities
|
|
Role/Capability
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
12/12/12
|
|
#23377
|
map_meta_cap() throws error from has_cap() from current_user_can()
|
|
Role/Capability
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
03/07/13
|
|
#21425
|
the 'edit_users' capability also allows 'promote_users'
|
|
Role/Capability
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
09/22/12
|
|
#16291
|
user role drop down inaccurate on ms-sites.php
|
|
Role/Capability
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
01/18/11
|
|
#22895
|
user_can_admin_menu() is Type-Insensitive for Users who Can't Create Pages
|
|
Role/Capability
|
normal
|
normal
|
3.6
|
defect (bug)
|
|
12/29/12
|
|
#14479
|
Add filter hook to 'is_super_admin()' function
|
benward
|
Role/Capability
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
11/18/10
|
|
#15819
|
Create user_can_for_blog function
|
|
Role/Capability
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
12/13/12
|
|
#2531
|
Functions for registering additional capabilities and getting a list of all capabilities
|
|
Role/Capability
|
normal
|
normal
|
Future Release
|
enhancement
|
|
06/28/12
|
|
#17924
|
Make Integrating Multiple Roles Per User Easier for Plugin Authors
|
|
Role/Capability
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
05/16/13
|
|
#14986
|
Make WordPress roles/capabilities more secure (edit_users related)
|
|
Role/Capability
|
normal
|
normal
|
Future Release
|
enhancement
|
|
01/13/11
|
|
#22968
|
No way to view_others_posts without being forced to have edit_others_posts enabled
|
|
Role/Capability
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
|
12/18/12
|
|
#10201
|
Remove user-specific caps
|
|
Role/Capability
|
normal
|
normal
|
Future Release
|
enhancement
|
early
|
01/04/13
|
|
#22959
|
Show all roles in user list table
|
|
Role/Capability
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
05/14/13
|
|
#23391
|
User in contributor role can add images to post only via the text editor
|
|
Role/Capability
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
|
02/05/13
|
|
#13269
|
Ability to list by user role in wp_dropdown_users
|
|
Role/Capability
|
normal
|
normal
|
Future Release
|
feature request
|
|
10/27/10
|
|
#5942
|
Add Owner role
|
|
Role/Capability
|
normal
|
normal
|
Future Release
|
feature request
|
|
04/10/11
|
|
#17253
|
Author role should be able to make/edit pages (a.k.a. let's get with the times)
|
|
Role/Capability
|
normal
|
normal
|
Future Release
|
feature request
|
|
08/23/12
|
|
#17254
|
Contributors should be able to upload
|
|
Role/Capability
|
normal
|
normal
|
Awaiting Review
|
feature request
|
|
09/10/11
|
|
#24293
|
$allowedposttags to allow value for <li>
|
|
Security
|
normal
|
normal
|
3.6
|
defect (bug)
|
commit
|
05/09/13
|
|
#13377
|
Add more sanitization in _cleanup_header_comment
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
01/30/11
|
|
#10980
|
DoS in wp-trackbacks
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
10/21/09
|
|
#16822
|
FORCE_SSL_LOGIN causes wp-login.php to have an incorrect https link
|
jakub.tyrcha*
|
Security
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
09/10/11
|
|
#10267
|
Login form SSL is confusing
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
11/24/09
|
|
#11813
|
Post password stored as plaintext
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
09/17/12
|
|
#10268
|
Profile and Edit user pages should be secure too
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
11/13/10
|
|
#16483
|
Visibility: password-protected exposes multiple pages
|
|
Security
|
normal
|
minor
|
Future Release
|
defect (bug)
|
dev-feedback
|
03/18/13
|
|
#13051
|
admin_url() and site_url() shouldn't need esc_url()
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
11/13/10
|
|
#12402
|
make addslashes_gpc() use addslashes() fix to use real_escape, rather than addslashes
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
11/13/10
|
|
#9207
|
redirect_to wp-admin Should Force SSL If FORCE_SSL_ADMIN is enabled
|
hakre*
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
reporter-feedback
|
04/06/13
|
|
#11623
|
review options list and update sanitize_option()
|
dd32*
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
early
|
11/13/10
|
|
#14148
|
wp_get_attachment_url() is not url encoding
|
|
Security
|
normal
|
major
|
Future Release
|
defect (bug)
|
has-patch
|
12/20/10
|
|
#19415
|
wp_nav_menu showing private/conctepts posts without rights
|
|
Security
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
|
11/01/12
|
|
#14803
|
Admins should be warned if authentication keys and salts have the default phrase
|
|
Security
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
08/06/12
|
|
#21022
|
Allow bcrypt to be enabled via filter for pass hashing
|
|
Security
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
03/05/13
|
|
#15277
|
FORCE_SSL_LOGIN or _ADMIN go to death loops when using an load-balancer
|
|
Security
|
normal
|
normal
|
Future Release
|
enhancement
|
|
12/29/10
|
|
#10151
|
HTML5 <video> elements stripped in kses.php
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
01/05/12
|
|
#10741
|
Include user's IP address in the lost password message
|
ryan
|
Security
|
normal
|
minor
|
Future Release
|
enhancement
|
has-patch
|
11/20/09
|
|
#24063
|
Introduce some more _doing_it_wrong() calls in nonce functions
|
|
Security
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
has-patch
|
04/12/13
|
|
#20779
|
Recommend a user updates keys/salts in maint/repair.php
|
|
Security
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
06/27/12
|
|
#20276
|
Tie nonces to the current session
|
|
Security
|
normal
|
normal
|
Future Release
|
enhancement
|
|
01/28/13
|
|
#20060
|
wp_redirect() doesn't exit
|
|
Security
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
02/27/12
|
|
#20140
|
Ask old password to change user password
|
tman4506*
|
Security
|
normal
|
normal
|
Awaiting Review
|
feature request
|
dev-feedback
|
08/26/12
|
|
#10237
|
Implement Content Security Policy to prevent XSS
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
feature request
|
|
06/20/12
|
|
#10850
|
Make register_setting available on the front-end
|
ryan
|
Security
|
normal
|
normal
|
Future Release
|
feature request
|
|
09/25/09
|
|
#21737
|
Users should have to jump through hoops to set passwords of their choosing, and we should guard better against weak passwords
|
westi*
|
Security
|
normal
|
normal
|
Awaiting Review
|
feature request
|
|
04/18/13
|
|
#21924
|
add action / filter to wp-login.php so we can replace WordPress login and force using 3rd party login
|
|
Security
|
normal
|
normal
|
Awaiting Review
|
feature request
|
|
09/19/12
|
|
#17227
|
wp should work around bug in move_uploaded_file for tighter security
|
|
Security
|
normal
|
normal
|
Awaiting Review
|
feature request
|
|
11/17/11
|
|
#23798
|
Audio Shortcode: Fallback link gets cropped by fixed-height container.
|
|
Shortcodes
|
normal
|
normal
|
3.6
|
defect (bug)
|
has-patch
|
04/15/13
|
|
#23801
|
Audio Shortcode: MP3s Display above plain text.
|
|
Shortcodes
|
normal
|
normal
|
3.6
|
defect (bug)
|
|
05/16/13
|
|
#15694
|
Caption Shortcode I/O Intolerant of "]" Char
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
02/27/12
|
|
#14380
|
Caption shortcode inserts inline style forcing width of containing div
|
nacin*
|
Shortcodes
|
normal
|
minor
|
Future Release
|
defect (bug)
|
dev-feedback
|
01/31/13
|
|
#19639
|
Enhancement: request: filter support before shortcodes are parsed or convert " into "
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
12/22/11
|
|
#19927
|
Improve support escaping a shortcode tag
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
01/30/12
|
|
#7045
|
No name shortcode atts
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
11/01/12
|
|
#23694
|
Shortcode attributes mess up html strings
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
03/07/13
|
|
#23517
|
Shortcode: if last parameter ends with '/', it is mistaken for self-closing shortcode closure
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
02/19/13
|
|
#12061
|
Treatment of shortcodes by wpautop is incomplete
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
01/19/13
|
|
#18776
|
balanceTags should ignore shortcodes & their content
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
04/27/12
|
|
#21158
|
different result when shortcode atribute without value
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
07/04/12
|
|
#23307
|
shortcode_parse_atts may return empty string
|
|
Shortcodes
|
normal
|
minor
|
Awaiting Review
|
defect (bug)
|
has-patch
|
01/28/13
|
|
#22272
|
shortcode_unautop() Doesn't Account for Opening/Closing Shortcode tags each Being on Their Own Line
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
10/24/12
|
|
#22127
|
strange behaviour with shortcode with the_content filter
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
10/08/12
|
|
#24085
|
wpautop filter and shortcodes
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
05/17/13
|
|
#15434
|
Allow escaped quotes in shortcode atts
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
04/06/11
|
|
#12368
|
Allow setting limit in do_shortcode()
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
enhancement
|
reporter-feedback
|
03/08/10
|
|
#18558
|
Handling of dormant shortcodes is inelegant
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
has-patch
|
09/10/11
|
|
#23855
|
Leave Shortcode functions early, if there's no Shortcode delimiter
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
has-patch
|
04/04/13
|
|
#14481
|
Shortcode Enhancements
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
enhancement
|
needs-unit-tests
|
10/31/10
|
|
#23786
|
Shortcodes working inside HTML and PHP comments
|
|
Shortcodes
|
normal
|
minor
|
Awaiting Review
|
enhancement
|
|
03/15/13
|
|
#10702
|
Support for complex nested shorttags
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
11/06/12
|
|
#19968
|
Use named regular expression groups to simplify shortcodes code
|
|
Shortcodes
|
normal
|
minor
|
Awaiting Review
|
enhancement
|
|
02/06/12
|
|
#20659
|
Document available shortcodes in eg. new post page
|
|
Shortcodes
|
normal
|
normal
|
Awaiting Review
|
feature request
|
|
05/22/12
|
|
#12982
|
Shortcodes don't allow shortcodes in attributes
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
feature request
|
needs-unit-tests
|
04/15/10
|
|
#19044
|
$depth in start_el Walker_Category has null value
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
reporter-feedback
|
10/28/11
|
|
#8119
|
Attempts to edit deleted categories are not properly handled
|
westi
|
Taxonomy
|
normal
|
minor
|
Future Release
|
defect (bug)
|
has-patch
|
11/19/11
|
|
#23668
|
Check for empty slug input in register_taxonomy
|
|
Taxonomy
|
normal
|
normal
|
3.6
|
defect (bug)
|
dev-feedback
|
04/09/13
|
|
#13606
|
Comma's in taxonomy term names make them unpickable
|
|
Taxonomy
|
normal
|
major
|
Future Release
|
defect (bug)
|
|
11/13/10
|
|
#18553
|
Counting of categories doesn't work without refreshing?
|
|
Taxonomy
|
normal
|
minor
|
Awaiting Review
|
defect (bug)
|
|
09/03/11
|
|
#14073
|
Custom Taxonomies - Post Count wrong
|
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
reporter-feedback
|
11/13/10
|
|
#14370
|
Custom Taxonomies tagging Attachments
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
08/30/12
|
|
#15264
|
Deleting a term shared across taxonomies deletes all associated nav menus.
|
garyc40
|
Taxonomy
|
normal
|
major
|
3.6
|
defect (bug)
|
has-patch
|
01/12/13
|
|
#21842
|
Diffrerent Custom Taxonomy Unable to Have Same Term Name in Version 3.4.2
|
oneTarek
|
Taxonomy
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
reporter-feedback
|
09/14/12
|
|
#11156
|
Duplicate tag created if tag name contains ampersand
|
filosofo
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
|
11/13/10
|
|
#20850
|
Duplicate term insertion allowed after insertion with case differences
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
06/08/12
|
|
#16797
|
Edit Tags admin + custom post type + custom taxonomy
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
03/08/11
|
|
#12729
|
Fix [6326] - wp_unique_term_slug() when changing the parent
|
ryan
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
11/25/12
|
|
#23069
|
For plugins that create custom taxonomies, wp_delete_term does not work during plugin uninstall.
|
|
Taxonomy
|
normal
|
trivial
|
Awaiting Review
|
defect (bug)
|
|
01/02/13
|
|
#19112
|
Minor fix in category-template.php
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
11/16/11
|
|
#16101
|
Numeric term fields are strings
|
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
02/13/13
|
|
#19205
|
Orphaned categories can be created by accident
|
|
Taxonomy
|
normal
|
minor
|
Awaiting Review
|
defect (bug)
|
|
11/19/11
|
|
#9875
|
Postcount not set for parent in category dropdown.
|
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
07/01/10
|