From 155f8fd99a92e63e21708e40cdabc3148c6fc2b8 Mon Sep 17 00:00:00 2001 From: Andrew Ozz Date: Sun, 13 May 2018 11:03:57 +0000 Subject: [PATCH] Privacy: require `manage_privacy_options` capability for showing `WP_Privacy_Policy_Content::notice()`. Props ocean90. Fixes #44055. git-svn-id: https://develop.svn.wordpress.org/trunk@43248 602fd350-edb4-49c9-b593-d223f7449a82 --- src/wp-admin/includes/misc.php | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/src/wp-admin/includes/misc.php b/src/wp-admin/includes/misc.php index a8600f1d24..f15e5788cf 100644 --- a/src/wp-admin/includes/misc.php +++ b/src/wp-admin/includes/misc.php @@ -1565,6 +1565,10 @@ final class WP_Privacy_Policy_Content { return; } + if ( ! current_user_can( 'manage_privacy_options' ) ) { + return; + } + $policy_page_id = (int) get_option( 'wp_page_for_privacy_policy' ); if ( ! $policy_page_id || $policy_page_id != $post->ID ) {