From a03073ef0a5c663591aeecf42a1bb9c6cd0808b9 Mon Sep 17 00:00:00 2001 From: ryan Date: Sat, 25 Aug 2007 17:07:10 +0000 Subject: [PATCH] Add nonces to tag importers. Props xknown. fixes #4811 git-svn-id: http://svn.automattic.com/wordpress/trunk@5941 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-admin/import/utw.php | 6 ++++++ wp-admin/import/wp-cat2tag.php | 6 +++++- 2 files changed, 11 insertions(+), 1 deletion(-) diff --git a/wp-admin/import/utw.php b/wp-admin/import/utw.php index bc1ab5fca7..52e347ad12 100644 --- a/wp-admin/import/utw.php +++ b/wp-admin/import/utw.php @@ -31,6 +31,9 @@ class UTW_Import { } else { $step = (int) $_GET['step']; } + + if ( $step > 1 ) + check_admin_referer('import-utw'); // load the header $this->header(); @@ -102,6 +105,7 @@ class UTW_Import { } echo '
'; + wp_nonce_field('import-utw'); echo '

'; echo '
'; echo ''; @@ -137,6 +141,7 @@ class UTW_Import { } echo '
'; + wp_nonce_field('import-utw'); echo '

'; echo '
'; echo ''; @@ -155,6 +160,7 @@ class UTW_Import { echo '

' . sprintf( __('Done! %s tags where added!'), $tags_added ) . '

'; echo '
'; + wp_nonce_field('import-utw'); echo '

'; echo '
'; echo ''; diff --git a/wp-admin/import/wp-cat2tag.php b/wp-admin/import/wp-cat2tag.php index c31658ef49..5f2869e153 100644 --- a/wp-admin/import/wp-cat2tag.php +++ b/wp-admin/import/wp-cat2tag.php @@ -38,6 +38,7 @@ class WP_Categories_to_Tags { function categories_form() { print '
'; + wp_nonce_field('import-cat2tag'); print '