WordPress Managed: 7.1.2 security-fix package and automatic-update behavior
-
I’m looking for clarification on two WordPress Managed update questions.
- Package availability
Has a WordPress Managed package containing the fix for CVE-2026-87902—WordPress 7.1.2, or an equivalent documented fix—been published?
The latest entry I found in the Managed WordPress package-update thread (https://forum.cloudron.io/topic/2407/wordpress-managed-package-updates?page=2) was 3.20.2 / WordPress 7.1.1. If there’s a newer release or an existing discussion about this patch, a link would be appreciated. - Automatic-update behavior
The documentation explains how to disable automatic updates for an individual app, but I couldn’t find what happens to updates already in progress through the scheduling process.
If that app’s automatic-update toggle is turned off, what happens to:
- An available update displayed as pending;
- An update already queued for execution;
- An update already running?
Is the setting checked again before a queued task starts, or does it only prevent future scheduling?
Also, does Check for updates only refresh availability, with installation handled separately by the configured schedule, or can it initiate installation under the current automatic-update policy?
I’m trying to understand the supported maintenance process, not bypass Cloudron’s managed updater. Thanks for any documentation links or clarification.
- Package availability
-
Hello @milohiss
Has a WordPress Managed package containing the fix for CVE-2026-87902—WordPress 7.1.2, or an equivalent documented fix—been published?
If the update is not listed in the forum and not visible for your WordPress, no the update has not yet been published.
On your 2. questions, if automatic updates for an individual app is disabled:
updates already in progress through the scheduling process
An app update that is already actively running will not be cancled.
An available update displayed as pending
The update will be displayed in the dashboard, but will not auto update.
update already queued for execution
If queued it should be executed.
Adding, I understand queued as in 10x wordpress apps have been given the command to be updated.
3x are actively updating the other 7x are queued and waiting.
A difference would be sceduled updates.
So if 10x wordpress instances have an update avilable and the next schedule is for e.g.: 18:00 o'clock.
If automatic updates for these 10x wordpress are now disabled they should not be updated at 18:00 o'clock.An update already running
Same as above, already running updates should not be cancled
-
Hello @milohiss
Has a WordPress Managed package containing the fix for CVE-2026-87902—WordPress 7.1.2, or an equivalent documented fix—been published?
If the update is not listed in the forum and not visible for your WordPress, no the update has not yet been published.
On your 2. questions, if automatic updates for an individual app is disabled:
updates already in progress through the scheduling process
An app update that is already actively running will not be cancled.
An available update displayed as pending
The update will be displayed in the dashboard, but will not auto update.
update already queued for execution
If queued it should be executed.
Adding, I understand queued as in 10x wordpress apps have been given the command to be updated.
3x are actively updating the other 7x are queued and waiting.
A difference would be sceduled updates.
So if 10x wordpress instances have an update avilable and the next schedule is for e.g.: 18:00 o'clock.
If automatic updates for these 10x wordpress are now disabled they should not be updated at 18:00 o'clock.An update already running
Same as above, already running updates should not be cancled
Thanks for the earlier clarification. Our WordPress Managed app now offers package 3.20.3-1, showing WordPress 7.1.2, while the public announcement describes 3.20.3.
What changed in the -1 revision? Does it introduce any runtime, dependency, migration or minimum-Cloudron-version changes beyond the documented WordPress 7.1.2 security update?
-
Hello @milohiss
The @wordpress-managed version3.20.3had an issue where old installations did not setHTTPS=oncorrectly and3.20.3-1fixes this issue.
From a SemVer standpoint3.20.3-1is lower than3.20.3so adding a changelog entry for3.20.3-1after3.20.3would be considered wrong.
A long time ago we decided to use the$VERSION-Xformat as means for the Cloudron app store to directly offer the-Xversion instead of the$VERSIONso the faulty version is skipped.
Please apologize this confusion.
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login