Skip to:
Content

BuddyPress.org

Changeset 12624


Ignore:
Timestamp:
04/21/2020 06:02:58 PM (3 months ago)
Author:
boonebgorges
Message:

Add nonces to xProfile field deletion links.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/bp-xprofile/bp-xprofile-admin.php

    r12596 r12624  
    565565    global $message, $type;
    566566
     567    check_admin_referer( 'bp_xprofile_delete_field-' . $field_id, 'bp_xprofile_delete_field' );
     568
    567569    // Switch type to 'option' if type is not 'field'.
    568570    // @todo trust this param.
     
    728730
    729731                    <div class="delete-button">
    730                         <a class="confirm submit-delete deletion" href="<?php echo esc_url( $field_delete_url ); ?>"><?php _ex( 'Delete', 'Delete field link', 'buddypress' ); ?></a>
     732                        <a class="confirm submit-delete deletion" href="<?php echo esc_url( wp_nonce_url( $field_delete_url, 'bp_xprofile_delete_field-' . $field->id, 'bp_xprofile_delete_field' ) ); ?>"><?php _ex( 'Delete', 'Delete field link', 'buddypress' ); ?></a>
    731733                    </div>
    732734
Note: See TracChangeset for help on using the changeset viewer.