Make WordPress Core


Ignore:
Timestamp:
05/02/2006 10:36:06 PM (20 years ago)
Author:
ryan
Message:

Nonce from above. #2678

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/categories.php

    r3728 r3759  
    2525case 'addcat':
    2626
    27     check_admin_referer();
     27    check_admin_referer('add-category');
    2828
    2929    if ( !current_user_can('manage_categories') )
     
    3636
    3737case 'delete':
    38 
    39     check_admin_referer();
     38    $cat_ID = (int) $_GET['cat_ID'];
     39    check_admin_referer('delete-category' .  $cat_ID);
    4040
    4141    if ( !current_user_can('manage_categories') )
    4242        die (__('Cheatin’ uh?'));
    4343
    44     $cat_ID = (int) $_GET['cat_ID'];
    4544    $cat_name = get_catname($cat_ID);
    4645
     
    6867 <h2><?php _e('Edit Category') ?></h2>
    6968 <form name="editcat" action="categories.php" method="post">
     69      <?php wp_nonce_field('update-category' .  $category->cat_ID); ?>
    7070      <table class="editform" width="100%" cellspacing="2" cellpadding="5">
    7171        <tr>
     
    100100
    101101case 'editedcat':
    102     check_admin_referer();
     102    $cat_ID = (int) $_POST['cat_ID'];
     103    check_admin_referer('update-category' . $cat_ID);
    103104
    104105    if ( !current_user_can('manage_categories') )
     
    158159    <h2><?php _e('Add New Category') ?></h2>
    159160    <form name="addcat" id="addcat" action="categories.php" method="post">
     161        <?php wp_nonce_field('add-category'); ?>
    160162        <div class="alignleft"><?php _e('Name:') ?><br />
    161163        <input type="text" name="cat_name" id="cat_name" value="" /></p>
Note: See TracChangeset for help on using the changeset viewer.