Make WordPress Core


Ignore:
Timestamp:
01/11/2017 01:31:57 AM (8 years ago)
Author:
aaroncampbell
Message:

Add nonce for widget accessibility mode.

Props vortfu.

See #23328.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/wp-admin/widgets.php

    r39541 r39760  
    2323$widgets_access = get_user_setting( 'widgets_access' );
    2424if ( isset($_GET['widgets-access']) ) {
     25    check_admin_referer( 'widgets-access' );
     26
    2527    $widgets_access = 'on' == $_GET['widgets-access'] ? 'on' : 'off';
    2628    set_user_setting( 'widgets_access', $widgets_access );
Note: See TracChangeset for help on using the changeset viewer.