Commit b605496461 for wordpress.org
commit b6054964614c815851807a4d094a9e6c7cc48ef0
Author: jorbin <jorbin@git.wordpress.org>
Date: Tue Oct 6 14:50:30 2026 +0000
REST API: Require both capabilities to change a post's sticky status.
Props xknown, jeremyfelt, jorbin.
Built from https://develop.svn.wordpress.org/trunk@64130
git-svn-id: http://core.svn.wordpress.org/trunk@63286 1a063a9b-81f0-0310-95a4-ce76da25c4cd
diff --git a/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php b/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php
index ee3e6b4959..443f839dba 100644
--- a/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php
+++ b/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php
@@ -703,7 +703,7 @@ class WP_REST_Posts_Controller extends WP_REST_Controller {
);
}
- if ( ! empty( $request['sticky'] ) && ! current_user_can( $post_type->cap->edit_others_posts ) && ! current_user_can( $post_type->cap->publish_posts ) ) {
+ if ( ! empty( $request['sticky'] ) && ( ! current_user_can( $post_type->cap->edit_others_posts ) || ! current_user_can( $post_type->cap->publish_posts ) ) ) {
return new WP_Error(
'rest_cannot_assign_sticky',
__( 'Sorry, you are not allowed to make posts sticky.' ),
@@ -914,7 +914,7 @@ class WP_REST_Posts_Controller extends WP_REST_Controller {
);
}
- if ( ! empty( $request['sticky'] ) && ! current_user_can( $post_type->cap->edit_others_posts ) && ! current_user_can( $post_type->cap->publish_posts ) ) {
+ if ( isset( $request['sticky'] ) && is_sticky( $post->ID ) !== (bool) $request['sticky'] && ( ! current_user_can( $post_type->cap->edit_others_posts ) || ! current_user_can( $post_type->cap->publish_posts ) ) ) {
return new WP_Error(
'rest_cannot_assign_sticky',
__( 'Sorry, you are not allowed to make posts sticky.' ),
diff --git a/wp-includes/version.php b/wp-includes/version.php
index 4153773607..58bea66223 100644
--- a/wp-includes/version.php
+++ b/wp-includes/version.php
@@ -16,7 +16,7 @@
*
* @global string $wp_version
*/
-$wp_version = '7.2-alpha-64129';
+$wp_version = '7.2-alpha-64130';
/**
* Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.