Wordpress 3.0.6
[autoinstalls/wordpress.git] / wp-admin / media-upload.php
index bd21e4bc4982534b13b197b6ee4073e3d97e69af..fc3bf3253c5c6ee89f3c1ea442aabd6da5fc6607 100644 (file)
@@ -35,6 +35,7 @@ if ( isset($_GET['inline']) ) {
        $errors = array();
 
        if ( isset($_POST['html-upload']) && !empty($_FILES) ) {
+               check_admin_referer('media-form');
                // Upload File button was clicked
                $id = media_handle_upload('async-upload', $_REQUEST['post_id']);
                unset($_FILES);