Make WordPress Core


Ignore:
Timestamp:
05/16/2023 03:23:11 PM (2 years ago)
Author:
SergeyBiryukov
Message:

Grouped backports to the 4.2 branch.

  • Media: Prevent CSRF setting attachment thumbnails.

Merges [55764] to the 4.2 branch.
Props dd32, isabel_brison, martinkrcho, matveb, ocean90, paulkevan, peterwilsoncc, timothyblynjacobs, xknown, youknowriad.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • branches/4.2/src/wp-admin/includes/ajax-actions.php

    r45953 r55775  
    20252025    }
    20262026
     2027    if ( false === check_ajax_referer( 'set-attachment-thumbnail', '_ajax_nonce', false ) ) {
     2028        wp_send_json_error();
     2029    }
     2030
    20272031    $post_ids = array();
    20282032    // For each URL, try to find its corresponding post ID.
Note: See TracChangeset for help on using the changeset viewer.