[wp-hackers] WordPress plugin update bugs

Travis Snoozy ai2097 at users.sourceforge.net
Sun Sep 30 12:08:51 GMT 2007

Hey folks,

  I've been having some trouble with getting the plugin upgrade feature
to work for my plugin[1]. I poked around and inferred a bit about how
the update system backend works[2]. Unfortunately, I also found a few
less-than-ideal behaviors, two of which stem from the assumption that
all plugins are hosted with WordPress:


I'm pretty concerned about 5115 and 5117 security-wise, since the user
can get the impression that all his/her plugins are up-to-date when
they're not. Any extra eyes on this feature or comments on the bugs
would be appreciated.



In Series maintainer
Random coder & quality guy

[2] http://remstate.com/2007/09/30/plugin-updates-and-wordpress-23/

More information about the wp-hackers mailing list