Make WordPress Core

Ticket #50882: 46872.diff

File 46872.diff, 774 bytes (added by garrett-eclipse, 4 years ago)

Apply action="users.php" to the forms in users.php to nullify the action2/doaction2 params that get inherited from the URL when no action set on the form.

  • src/wp-admin/users.php

     
    266266
    267267                require_once ABSPATH . 'wp-admin/admin-header.php';
    268268                ?>
    269         <form method="post" name="updateusers" id="updateusers">
     269        <form action="users.php" method="post" name="updateusers" id="updateusers">
    270270                <?php wp_nonce_field( 'delete-users' ); ?>
    271271                <?php echo $referer; ?>
    272272
     
    408408
    409409                require_once ABSPATH . 'wp-admin/admin-header.php';
    410410                ?>
    411         <form method="post" name="updateusers" id="updateusers">
     411        <form action="users.php" method="post" name="updateusers" id="updateusers">
    412412                <?php wp_nonce_field( 'remove-users' ); ?>
    413413                <?php echo $referer; ?>
    414414