Wordpress/wp-admin
Andrew Nacin acc1b0f220 Customize requires edit_theme_options. If you only have switch_themes (rare, but a case that core supports), you should not have access. fixes #21413.
git-svn-id: https://develop.svn.wordpress.org/trunk@24049 602fd350-edb4-49c9-b593-d223f7449a82
2013-04-22 19:37:26 +00:00
..
css Revert [23871] - Customize should be added to the menu, but not hacked in as first. see #21413. 2013-04-22 19:33:39 +00:00
images Post Format UI. 2013-03-29 03:35:41 +00:00
includes Revert [23871] - Customize should be added to the menu, but not hacked in as first. see #21413. 2013-04-22 19:33:39 +00:00
js Ensure that the resulting post time is localized after the date is changed. props SergeyBiryukov. fixes #24072. 2013-04-22 19:04:02 +00:00
maint
network Use API instead of bare SQL queries in site-users.php. 2013-04-12 13:35:45 +00:00
user
about.php
admin-ajax.php Logged out warnings, heartbeat: remove nopriv_autosave as it doubles the functionality of the logged out warnings, move wp_ajax_nopriv_heartbeat() under No-privilege Ajax handlers in ajax-actions.php, see #23295, see #23216 2013-03-13 23:54:12 +00:00
admin-footer.php
admin-functions.php
admin-header.php Consistently show "Customize" item in the admin menu. props ethitter. fixes #21413. 2013-03-29 23:25:06 +00:00
admin-post.php
admin.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
async-upload.php
comment.php
credits.php
custom-background.php
custom-header.php Sanity checks on image metadata to avoid warnings, etc. 2013-03-29 20:51:35 +00:00
customize.php
edit-comments.php Ensure the referer functions operate completely on unslashed data: wp_referer_field(), wp_original_referer_field(), wp_get_referer(), wp_get_original_referer(). 2013-03-01 17:58:43 +00:00
edit-form-advanced.php Post Formats: use the content body for the body of the Quote post format. 2013-04-18 18:07:58 +00:00
edit-form-comment.php Add `.edit-form-section` class to the comment edit form for correct spacing. fixes #23240. 2013-04-10 19:20:13 +00:00
edit-link-form.php Remove dead code. Removed in [23445], accidentally reinstated in [23554]. This was found during wp_reset_vars() cleanup. see #21767. 2013-04-06 20:47:12 +00:00
edit-tag-form.php
edit-tags.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
edit.php Bulk actions: do not move locked posts to the trash, props pdclark, see #23792 2013-03-18 21:11:06 +00:00
export.php
freedoms.php
import.php
index.php
install-helper.php
install.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:14:09 +00:00
link-add.php
link-manager.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:14:09 +00:00
link-parse-opml.php
link.php
load-scripts.php
load-styles.php
media-new.php Escape form action urls with esc_url() rather than esc_attr(). 2013-03-18 14:01:25 +00:00
media-upload.php
media.php
menu-header.php Revert [23871] - Customize should be added to the menu, but not hacked in as first. see #21413. 2013-04-22 19:33:39 +00:00
menu.php Customize requires edit_theme_options. If you only have switch_themes (rare, but a case that core supports), you should not have access. fixes #21413. 2013-04-22 19:37:26 +00:00
moderation.php
ms-admin.php
ms-delete-site.php
ms-edit.php
ms-options.php
ms-sites.php
ms-themes.php
ms-upgrade-network.php
ms-users.php
my-sites.php
nav-menus.php Remove _wp_delete_nav_menu(). wp_delete_nav_menu() should instead remove the menu from theme locations, which was the only difference between the functions. see #23119. 2013-04-04 04:28:12 +00:00
network.php Make get_home_path() return consistent slashes. fixes #23175. 2013-03-12 11:04:14 +00:00
options-discussion.php Consistently apply class="title" to our options page h3 tags. 2013-04-16 20:19:29 +00:00
options-general.php
options-head.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:14:09 +00:00
options-media.php Consistently apply class="title" to our options page h3 tags. 2013-04-16 20:19:29 +00:00
options-permalink.php Consistently apply class="title" to our options page h3 tags. 2013-04-16 20:19:29 +00:00
options-reading.php
options-writing.php Consistently apply class="title" to our options page h3 tags. 2013-04-16 20:19:29 +00:00
options.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:14:09 +00:00
plugin-editor.php Don't unslash variables that came from wp_reset_vars(). see #21767. 2013-03-01 18:59:54 +00:00
plugin-install.php
plugins.php
post-new.php
post.php Revisions: move the call to _wp_upgrade_revisions_of_post() to edit-form-advanced.php, in the code block checking whether we should show the revisions postbox. See #16215 2013-04-06 23:43:05 +00:00
press-this.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:14:09 +00:00
profile.php
revision.php Revisions: Clean up JavaScript variable names, see #23901. 2013-04-17 19:34:21 +00:00
setup-config.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:14:09 +00:00
theme-editor.php Don't unslash variables that came from wp_reset_vars(). see #21767. 2013-03-01 18:59:54 +00:00
theme-install.php
themes.php Revert [23871] - Customize should be added to the menu, but not hacked in as first. see #21413. 2013-04-22 19:33:39 +00:00
tools.php
update-core.php Escape form action urls with esc_url() rather than esc_attr(). 2013-03-18 14:01:25 +00:00
update.php
upgrade-functions.php
upgrade.php Always wp_unslash() the return of wp_get_referer(). 2013-03-01 17:20:32 +00:00
upload.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:14:09 +00:00
user-edit.php Cleanup additional capabilities display in user-edit.php. Mark a string for translation. 2013-03-18 13:27:57 +00:00
user-new.php Fix copy/paste error in user-new.php. props tivnet. fixes #24022. 2013-04-10 16:13:59 +00:00
users.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-03 16:30:38 +00:00
widgets.php