Make WordPress Core

Opened 12 days ago

Closed 12 days ago

Last modified 12 days ago

#55366 closed defect (bug) (invalid)

WordPress auto-updated plugin with auto-updates disabled

Reported by: vtxtools Owned by:
Milestone: Priority: normal
Severity: normal Version:
Component: Plugins Keywords:
Focuses: Cc:

Description

Hello,

As there are some updates that can break our site, we have automatic updates disabled for all plugins. Today, the plugin "Woocommerce" updated from version 6.3.0 to 6.3.1 automatically, causing a critical issue on our site. I looked at the changelog for this version, and it appears there was a fix for a security issue. So I am wondering if there is some criteria that would allow an automatic update of a plugin even if automatic updates are disabled. We understand the need to keep plugins up to date, I'm just curious if security was the reason for this unexpected behavior or if it's a bug.

Change History (3)

This ticket was mentioned in Slack in #meta by pbiron. View the logs.


12 days ago

#2 @Otto42
12 days ago

  • Milestone Awaiting Review deleted
  • Resolution set to invalid
  • Status changed from new to closed

The default setting for auto-updates is not "disabled". The default is to follow the recommendation of the WordPress.org systems. So yes, an automatic update was enabled for WooCommerce starting today for the security issue. https://developer.woocommerce.com/2022/03/10/woocommerce-3-5-10-6-3-1-security-releases/

WordPress has had auto-updating for plugins since WordPress 3.7. You can read more about this here: https://make.wordpress.org/plugins/2015/03/14/plugin-automatic-security-updates/

Last edited 12 days ago by Otto42 (previous) (diff)

#3 @SergeyBiryukov
12 days ago

  • Component changed from General to Plugins
Note: See TracTickets for help on using tickets.