Commit 9fae7806 authored by John James Jacoby's avatar John James Jacoby
Browse files

Check that `$_REQUEST['_wpnonce']` is not empty.

parent 0fc88fe6
Pipeline #849 skipped
......@@ -129,8 +129,8 @@ function wp_join_page_user_row_actions( $actions = array(), $user_object = array
*/
function wp_join_page_admin_maybe_approve_user() {
// Bail if not an approve action
if ( empty( $_REQUEST['action'] ) || empty( $_REQUEST['users'] ) || ( 'approve_user' !== $_REQUEST['action'] ) ) {
// Bail if missing required data
if ( empty( $_REQUEST['_wpnonce'] ) || empty( $_REQUEST['action'] ) || empty( $_REQUEST['users'] ) || ( 'approve_user' !== $_REQUEST['action'] ) ) {
return;
}
......
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment