Wordpress 3.1.1
[autoinstalls/wordpress.git] / wp-admin / media-upload.php
index 19eda096527327b9a1fb9c6cc276af9f08500bd1..81bbf5369a157298176651562d7ad200792498dd 100644 (file)
@@ -38,6 +38,7 @@ if ( isset($_GET['inline']) ) {
        $errors = array();
 
        if ( isset($_POST['html-upload']) && !empty($_FILES) ) {
+               check_admin_referer('media-form');
                // Upload File button was clicked
                $id = media_handle_upload('async-upload', $_REQUEST['post_id']);
                unset($_FILES);