diff --git a/wp-admin/comment.php b/wp-admin/comment.php
index d687514c33..851b5827f4 100644
--- a/wp-admin/comment.php
+++ b/wp-admin/comment.php
@@ -89,10 +89,9 @@ case 'mailapprovecomment':
break;
case 'deletecomment':
-
- check_admin_referer();
-
$comment = (int) $_REQUEST['comment'];
+ check_admin_referer('delete-comment' . $comment);
+
$p = (int) $_REQUEST['p'];
if ( isset($_REQUEST['noredir']) ) {
$noredir = true;
@@ -123,10 +122,9 @@ case 'deletecomment':
break;
case 'unapprovecomment':
-
- check_admin_referer();
-
$comment = (int) $_GET['comment'];
+ check_admin_referer('unapprove-comment' . $comment);
+
$p = (int) $_GET['p'];
if (isset($_GET['noredir'])) {
$noredir = true;
@@ -151,10 +149,9 @@ case 'unapprovecomment':
break;
case 'approvecomment':
-
- check_admin_referer();
-
$comment = (int) $_GET['comment'];
+ check_admin_referer('approve-comment' . $comment);
+
$p = (int) $_GET['p'];
if (isset($_GET['noredir'])) {
$noredir = true;
@@ -184,7 +181,7 @@ case 'approvecomment':
case 'editedcomment':
- check_admin_referer();
+ check_admin_referer('update-comment');
edit_comment();
diff --git a/wp-admin/edit-comments.php b/wp-admin/edit-comments.php
index de3d814d9d..eff027780a 100644
--- a/wp-admin/edit-comments.php
+++ b/wp-admin/edit-comments.php
@@ -51,7 +51,7 @@ function getNumChecked(form)
|
comment_post_ID) ) {
echo "
" . __('Edit') . '';
- echo ' |
comment_author, 1)) . "' );\">" . __('Delete') . ' ';
+ echo ' |
comment_author, 1)) . "' );\">" . __('Delete') . ' ';
if ( ('none' != $comment_status) && ( current_user_can('moderate_comments') ) ) {
- echo '
| ' . __('Unapprove') . ' ';
- echo '
| ' . __('Approve') . ' ';
+ echo '
| ' . __('Unapprove') . ' ';
+ echo '
| ' . __('Approve') . ' ';
}
echo " |
comment_post_ID."&comment=".$comment->comment_ID."\" onclick=\"return deleteSomething( 'comment-as-spam', $comment->comment_ID, '" . sprintf(__("You are about to mark as spam this comment by "%s".\\n"Cancel" to stop, "OK" to mark as spam."), wp_specialchars( $comment->comment_author, 1 )) . "' );\">" . __('Spam') . " ";
}
@@ -150,8 +150,9 @@ $post_title = ('' == $post_title) ? "# $comment->comment_post_ID" : $post_title;
} elseif ('edit' == $mode) {
if ($comments) {
- echo '