WordPress.org

Make WordPress Core

Opened 6 years ago

Closed 6 years ago

Last modified 6 years ago

#19824 closed defect (bug) (fixed)

Capability checks missing for some links after a plugin/theme upgrade

Reported by: linuxologos Owned by: nacin
Milestone: 3.5 Priority: normal
Severity: normal Version: 3.0
Component: Upgrade/Install Keywords: has-patch
Focuses: Cc:

Description

After a plugin's/theme's update has been finished through the Dashboard > Updates (update-core.php) screen, the "Return to Plugins page" or "Return to Themes page" links are offered, but there is no check if current user can access those pages (plugins.php/themes.php).

This problem can show up, if a user is given the update_core and one or both of update_plugins, update_themes capabilities, but doesn't have any of activate_plugins, edit_theme_options, switch_themes capabilities.

Attachments (1)

19824.patch (1.5 KB) - added by linuxologos 6 years ago.

Download all attachments as: .zip

Change History (6)

@linuxologos
6 years ago

#1 @nacin
6 years ago

  • Milestone changed from Awaiting Review to 3.5

Looks good.

Worth noting that update-core.php can only be accessed if you have the update_core cap. Perhaps that page should be changed to allow for someone to have only update_plugins and/or update_themes?

#2 @nacin
6 years ago

In [21195]:

Cap checks in the upgrader so we do not show links the user cannot access. props linuxologos for the initial patch. see #19824.

Also fixes a rare fatal error when theme_info is not set when updating a theme that is already up to date.

#3 @nacin
6 years ago

In [21196]:

Have the correct screen icon in place when the top level Plugins menu is plugin-install.php. This occurs when the user can install but not activate plugins. see #19824.

#4 @nacin
6 years ago

  • Owner set to nacin
  • Resolution set to fixed
  • Status changed from new to closed

In [21197]:

Cap checks for links in the upgrader, for plugins. fixes #19824.

#5 @nacin
6 years ago

In [21200]:

Un-indent after [21198]. see #19824.

Note: See TracTickets for help on using tickets.