WordPress/wp-admin
Sergey Biryukov 55f6ac107d Grouped backports to the 4.5 branch.
- Media: Prevent CSRF setting attachment thumbnails.
- Embeds: Add protocol validation for WordPress Embed code.

Merges [55763] and [55764] to the 4.5 branch.
Props dd32, isabel_brison, martinkrcho, matveb, ocean90, paulkevan, peterwilsoncc, timothyblynjacobs, xknown, youknowriad.
Built from https://develop.svn.wordpress.org/branches/4.5@55780


git-svn-id: http://core.svn.wordpress.org/branches/4.5@55292 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2023-05-16 15:40:23 +00:00
..
css Build/Test Tools: Support NodeJS 14.x in the 4.5 branch. 2021-02-05 04:20:44 +00:00
images Add grunt prerelease task 2016-03-10 05:37:27 +00:00
includes Grouped backports to the 4.5 branch. 2023-05-16 15:40:23 +00:00
js Build/Test Tools: Support NodeJS 14.x in the 4.5 branch. 2021-02-05 04:20:44 +00:00
maint
network General: WordPress updates 2020-10-29 19:02:24 +00:00
user
about.php Grouped backports to the 4.5 branch. 2023-05-16 15:40:23 +00:00
admin-ajax.php
admin-footer.php
admin-functions.php
admin-header.php General: WordPress updates 2020-10-29 19:02:24 +00:00
admin-post.php
admin.php Taxonomy: After [36874], run the correct load-edit-tags.php hook on the new term edit page. 2016-03-27 15:16:29 +00:00
async-upload.php Escape the output in wp_ajax_upload_attachment(). 2019-09-04 16:37:09 +00:00
comment.php Make Moderate Comment Screen Great Again by showing links 2016-04-06 00:35:27 +00:00
credits.php 4.5 About Page, second round. 2016-04-10 02:03:29 +00:00
custom-background.php General: WordPress updates 2020-10-29 19:02:24 +00:00
custom-header.php General: WordPress updates 2020-10-29 19:02:24 +00:00
customize.php Customize: Ignore invalid customization sessions. 2017-05-16 12:16:31 +00:00
edit-comments.php
edit-form-advanced.php Editor: Remove trailing space from a help text string. 2016-04-05 10:54:29 +00:00
edit-form-comment.php Comments: On the Edit Comment screen do not show the permalink for unapproved comments. 2016-03-10 21:18:27 +00:00
edit-link-form.php
edit-tag-form.php Taxonomy/Users: Use correct escaping function for URLs. 2017-09-19 21:30:32 +00:00
edit-tags.php
edit.php
export.php
freedoms.php 4.5 About Page, second round. 2016-04-10 02:03:29 +00:00
import.php Accessibility: Improve accessibility for the Plugin details modal. 2016-03-10 22:37:26 +00:00
index.php
install-helper.php
install.php
link-add.php
link-manager.php
link-parse-opml.php
link.php Fix syntax for single- and multi-line comments in wp-admin-directory files. 2014-07-17 09:14:16 +00:00
load-scripts.php
load-styles.php
media-new.php General: WordPress updates 2020-10-29 19:02:24 +00:00
media-upload.php
media.php Media: Change wording for media files which aren't attached. 2016-03-08 17:43:25 +00:00
menu-header.php Docs: Correct grammar when referring to "a URL" vs "an URL" in several places. 2016-03-12 12:39:27 +00:00
menu.php
moderation.php
ms-admin.php
ms-delete-site.php
ms-edit.php
ms-options.php
ms-sites.php
ms-themes.php
ms-upgrade-network.php
ms-users.php
my-sites.php
nav-menus.php Menus: Support nested array variables in POST data when saving menus. 2016-06-20 19:50:30 +00:00
network.php
options-discussion.php
options-general.php
options-head.php
options-media.php
options-permalink.php
options-reading.php
options-writing.php
options.php Media: Remove medium_large size from $whitelist_options['media'] in options.php. 2016-05-17 20:40:29 +00:00
plugin-editor.php General: Add missing URL-encoding and add extra hardening to plugin and template names when they're displayed in the admin area. 2017-09-19 10:32:31 +00:00
plugin-install.php
plugins.php Grouped backports to the 4.5 branch. 2022-08-30 15:49:21 +00:00
post-new.php
post.php Editor: Remove unwanted fields before saving posts. 2018-12-13 01:45:20 +00:00
press-this.php
profile.php
revision.php Revisions: Change the capability needed to view revision diffs to edit_post. 2016-06-21 14:27:33 +00:00
setup-config.php Setup config: Generate the default secret keys & salts from the local CSPRNG if available, falling back to the WordPress.org API and a backup psuedo random source. 2016-03-07 06:32:29 +00:00
term.php Taxonomy: After [36874], rename $term_id to $tag_ID in wp-admin/edit-tag-form.php. 2016-03-11 08:52:29 +00:00
theme-editor.php General: Add missing URL-encoding and add extra hardening to plugin and template names when they're displayed in the admin area. 2017-09-19 10:32:31 +00:00
theme-install.php Add Nonce to updating wporg_favorites user meta field 2016-03-30 18:36:26 +00:00
themes.php General: Backport several commits for release. 2020-06-10 18:54:52 +00:00
tools.php
update-core.php Updates: Translate plugin data on the Updates screen. 2017-01-11 11:40:38 +00:00
update.php
upgrade-functions.php
upgrade.php
upload.php Media: Fix typo introduced in [36887]. 2016-03-14 09:00:28 +00:00
user-edit.php Taxonomy/Users: Use correct escaping function for URLs. 2017-09-19 21:30:32 +00:00
user-new.php Hardening: Use a properly generated hash for the newbloguser key instead of a determinate substring. 2017-11-29 16:25:07 +00:00
users.php Use admin_url() for "Add New" links in wp-admin/users.php. 2016-03-09 19:09:50 +00:00
widgets.php Add nonce for widget accessibility mode. 2017-01-11 01:44:31 +00:00