From 3f5ab5b9bf15d7f5f21e966d23466ccce64d5ce5 Mon Sep 17 00:00:00 2001 From: westi Date: Sat, 6 Nov 2010 10:07:35 +0000 Subject: [PATCH] Extra cap checks. See #15326. git-svn-id: http://svn.automattic.com/wordpress/trunk@16222 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-admin/edit-comments.php | 4 +++- wp-admin/edit-tags.php | 4 +++- 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/wp-admin/edit-comments.php b/wp-admin/edit-comments.php index 7805a3da6..08606e5d8 100644 --- a/wp-admin/edit-comments.php +++ b/wp-admin/edit-comments.php @@ -8,7 +8,9 @@ /** WordPress Administration Bootstrap */ require_once('./admin.php'); - +if ( !current_user_can('edit_posts') ) + wp_die(__('Cheatin’ uh?')); + $wp_list_table = get_list_table('WP_Comments_List_Table'); $wp_list_table->check_permissions(); diff --git a/wp-admin/edit-tags.php b/wp-admin/edit-tags.php index c685452b9..fbfb9ca9e 100644 --- a/wp-admin/edit-tags.php +++ b/wp-admin/edit-tags.php @@ -8,7 +8,9 @@ /** WordPress Administration Bootstrap */ require_once('./admin.php'); - +if ( !current_user_can( $tax->cap->manage_terms ) ) + wp_die( __( 'Cheatin’ uh?' ) ); + $wp_list_table = get_list_table('WP_Terms_List_Table'); $wp_list_table->check_permissions();