diff --git a/wp-includes/pluggable-functions.php b/wp-includes/pluggable-functions.php index 8528ba8e13..067ac402a0 100644 --- a/wp-includes/pluggable-functions.php +++ b/wp-includes/pluggable-functions.php @@ -232,7 +232,9 @@ function check_admin_referer($action = -1) { global $pagenow; $adminurl = strtolower(get_settings('siteurl')).'/wp-admin'; $referer = strtolower($_SERVER['HTTP_REFERER']); - if ( !wp_verify_nonce($_REQUEST['_wpnonce'], $action) ) { + if ( !wp_verify_nonce($_REQUEST['_wpnonce'], $action) && + !(-1 == $action && strstr($referer, $adminurl)) ) { + $html = "\n\n\n"; $html .= "\n\t" . __('WordPress Confirmation') . "\n"; $html .= "\n\n";