From 8d72fd31d48c9a884f4375b64944ad5e6504a0bb Mon Sep 17 00:00:00 2001 From: Jon Cave Date: Tue, 27 Aug 2013 13:56:17 +0000 Subject: [PATCH] Initialize kses filters if _wp_unfiltered_html_comment nonce isn't set. See #24752. git-svn-id: https://develop.svn.wordpress.org/trunk@25137 602fd350-edb4-49c9-b593-d223f7449a82 --- src/wp-comments-post.php | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/src/wp-comments-post.php b/src/wp-comments-post.php index d400ef0b70..3be4e64c6f 100644 --- a/src/wp-comments-post.php +++ b/src/wp-comments-post.php @@ -60,8 +60,10 @@ if ( $user->exists() ) { $comment_author = wp_slash( $user->display_name ); $comment_author_email = wp_slash( $user->user_email ); $comment_author_url = wp_slash( $user->user_url ); - if ( current_user_can( 'unfiltered_html' ) && isset( $_POST['_wp_unfiltered_html_comment'] ) ) { - if ( wp_create_nonce( 'unfiltered-html-comment_' . $comment_post_ID ) != $_POST['_wp_unfiltered_html_comment'] ) { + if ( current_user_can( 'unfiltered_html' ) ) { + if ( ! isset( $_POST['_wp_unfiltered_html_comment'] ) + || ! wp_verify_nonce( $_POST['_wp_unfiltered_html_comment'], 'unfiltered-html-comment_' . $comment_post_ID ) + ) { kses_remove_filters(); // start with a clean slate kses_init_filters(); // set up the filters }