Make WordPress Core


Ignore:
Timestamp:
06/03/2003 12:08:51 AM (23 years ago)
Author:
mikelittle
Message:

Fixed admin level security problem.
Plus an user -> a user

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/b2team.php

    r127 r149  
    3434
    3535    $user_data = get_userdata($id);
    36     $usertopromote_level = $user_data[13];
     36    $usertopromote_level = $user_data->user_level;
    3737
    3838    if ($user_level <= $usertopromote_level) {
    39         die('Can&#8217;t change the level of an user whose level is higher than yours.');
     39        die('Can&#8217;t change the level of a user whose level is higher than yours.');
    4040    }
    4141
     
    6666
    6767    if ($user_level <= $usertodelete_level)
    68         die('Can&#8217;t delete an user whose level is higher than yours.');
     68        die('Can&#8217;t delete a user whose level is higher than yours.');
    6969
    7070    $sql = "DELETE FROM $tableusers WHERE ID = $id";
     
    8484    ?>
    8585
    86 <div class="wrap"><p>Click on an user&#8217;s login name to see his complete profile.<br />
     86<div class="wrap"><p>Click on a user&#8217;s login name to see his complete profile.<br />
    8787    To edit your profile, click on your login name.</p>
    8888</div>
     
    192192    if ($user_level >= 3) { ?>
    193193<div class="wrap">
    194   <p>To delete an user, bring his level to zero, then click on the red X.<br />
    195     <strong>Warning:</strong> deleting an user also deletes all posts made by this user.
     194  <p>To delete a user, bring his level to zero, then click on the red X.<br />
     195    <strong>Warning:</strong> deleting a user also deletes all posts made by this user.
    196196  </p>
    197197</div>
Note: See TracChangeset for help on using the changeset viewer.