WordPress / Security-White-Paper

The WordPress Security White Paper, available directly on the WordPress.org site at https://wordpress.org/about/security/
96 stars 53 forks source link

Clarify unfiltered_html capability in Multisite #48

Closed iandunn closed 7 years ago

iandunn commented 7 years ago

In Multisite, regular Administrators of a single site do not have unfiltered_html, only super-administrator accounts do.

Historically, WordPress referred to a single site as a "blog" and a group of sites in a multisite network as a "site", but this is no longer the contemporary usage. A single site is now referred to as a "site", and a group of sites is referred to as a "network".