diff --git a/wp-admin/ms-delete-site.php b/wp-admin/ms-delete-site.php
index 8b26b0b6a3..2ae22339b7 100644
--- a/wp-admin/ms-delete-site.php
+++ b/wp-admin/ms-delete-site.php
@@ -34,6 +34,8 @@ screen_icon();
echo '
' . esc_html( $title ) . '
';
if ( isset( $_POST['action'] ) && $_POST['action'] == 'deleteblog' && isset( $_POST['confirmdelete'] ) && $_POST['confirmdelete'] == '1' ) {
+ check_admin_referer( 'delete-blog' );
+
$hash = wp_generate_password( 20, false );
update_option( 'delete_blog_hash', $hash );
@@ -68,11 +70,12 @@ Webmaster
- ';