wp_nonce_field() calls wp_referer_field() with too many args
|Reported by:||coffee2code||Owned by:||markjaquith|
In wp_nonce_field() in wp-includes/functions.php, a call is made to wp_referer_field() with two arguments. However, wp_referer_field() only accepts one argument.
wp_original_referer_field() accepts two arguments and is probably what was originally intended.
Refer to r7438 (specifically http://core.trac.wordpress.org/changeset/7438/trunk/wp-includes/functions.php). Mark added a second argument to wp_original_referer_field() while also adding the second (and technically invalid) argument to the call to wp_referer_field() in wp_nonce_field().
This leads me to believe that the wp_referer_field() call in question was intended to be changed to be a call to the updated wp_original_referer_field() function. This is also affirmed by the fact that there are no other calls to wp_referer_field() in the codebase except once in the livejournal importer.
As such, the attached patch changes the name of the function being called.
Change History (11)
- Cc vladimir@… added
- Resolution fixed deleted
- Status changed from closed to reopened
comment:6 markjaquith — 4 years ago
- Milestone changed from 2.9 to 3.0
- Owner changed from MarkJaquith to markjaquith
- Status changed from reopened to accepted
- Keywords commit added; early removed
- Severity changed from minor to normal