[wp-trac] [WordPress Trac] #55321: Adding new themes in releases without a global theme auto-update setting renders installations insecure

WordPress Trac noreply at wordpress.org
Wed Nov 2 22:37:42 UTC 2022


#55321: Adding new themes in releases without a global theme auto-update setting
renders installations insecure
-----------------------------+-----------------------------
 Reporter:  bertvandepoel    |       Owner:  pbiron
     Type:  enhancement      |      Status:  assigned
 Priority:  normal           |   Milestone:  Future Release
Component:  Upgrade/Install  |     Version:
 Severity:  normal           |  Resolution:
 Keywords:                   |     Focuses:  ui
-----------------------------+-----------------------------

Comment (by bertvandepoel):

 2023 is swiftly moving closer, and considering that the new theme is
 sometimes released a bit early (if I recall correctly) and I expect that
 things will get busy in December, I thought I'd bring this up again now. I
 still think it would be of great advantage to a huge amount of WordPress
 users that they won't get a new theme installed by automatic updates
 without their consent, which will then, unbeknownst to them, not get
 automatically updated when updates become available. So I hope that either
 the automatic installation or the fact it doesn't get marked for automatic
 updates even if all other components are will be revised.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/55321#comment:15>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list