Commit b605496461 for wordpress.org

commit b6054964614c815851807a4d094a9e6c7cc48ef0
Author: jorbin <jorbin@git.wordpress.org>
Date:   Tue Oct 6 14:50:30 2026 +0000

    REST API: Require both capabilities to change a post's sticky status.

    Props xknown, jeremyfelt, jorbin.

    Built from https://develop.svn.wordpress.org/trunk@64130


    git-svn-id: http://core.svn.wordpress.org/trunk@63286 1a063a9b-81f0-0310-95a4-ce76da25c4cd

diff --git a/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php b/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php
index ee3e6b4959..443f839dba 100644
--- a/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php
+++ b/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php
@@ -703,7 +703,7 @@ class WP_REST_Posts_Controller extends WP_REST_Controller {
 			);
 		}

-		if ( ! empty( $request['sticky'] ) && ! current_user_can( $post_type->cap->edit_others_posts ) && ! current_user_can( $post_type->cap->publish_posts ) ) {
+		if ( ! empty( $request['sticky'] ) && ( ! current_user_can( $post_type->cap->edit_others_posts ) || ! current_user_can( $post_type->cap->publish_posts ) ) ) {
 			return new WP_Error(
 				'rest_cannot_assign_sticky',
 				__( 'Sorry, you are not allowed to make posts sticky.' ),
@@ -914,7 +914,7 @@ class WP_REST_Posts_Controller extends WP_REST_Controller {
 			);
 		}

-		if ( ! empty( $request['sticky'] ) && ! current_user_can( $post_type->cap->edit_others_posts ) && ! current_user_can( $post_type->cap->publish_posts ) ) {
+		if ( isset( $request['sticky'] ) && is_sticky( $post->ID ) !== (bool) $request['sticky'] && ( ! current_user_can( $post_type->cap->edit_others_posts ) || ! current_user_can( $post_type->cap->publish_posts ) ) ) {
 			return new WP_Error(
 				'rest_cannot_assign_sticky',
 				__( 'Sorry, you are not allowed to make posts sticky.' ),
diff --git a/wp-includes/version.php b/wp-includes/version.php
index 4153773607..58bea66223 100644
--- a/wp-includes/version.php
+++ b/wp-includes/version.php
@@ -16,7 +16,7 @@
  *
  * @global string $wp_version
  */
-$wp_version = '7.2-alpha-64129';
+$wp_version = '7.2-alpha-64130';

 /**
  * Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.