Make WordPress Core


Ignore:
Timestamp:
05/04/2006 09:20:44 AM (20 years ago)
Author:
ryan
Message:

A couple more nonces. #2678

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/user-edit.php

    r3679 r3760  
    3333case 'update':
    3434
    35 check_admin_referer();
     35check_admin_referer('update-user' . $user_id);
    3636
    3737if (!current_user_can('edit_users'))
     
    7575
    7676<form name="profile" id="your-profile" action="user-edit.php" method="post">
     77<?php wp_nonce_field('update-user' . $user_ID) ?>
    7778<p>
    7879<input type="hidden" name="from" value="profile" />
Note: See TracChangeset for help on using the changeset viewer.