Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Offical apps | Community apps | Demo | Docs | Install
  1. Cloudron Forum
  2. WordPress (Managed)
  3. WordPress Managed: 7.1.2 security-fix package and automatic-update behavior

WordPress Managed: 7.1.2 security-fix package and automatic-update behavior

Scheduled Pinned Locked Moved WordPress (Managed)
4 Posts 2 Posters 72 Views 2 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    M
    milohiss
    wrote last edited by
    #1

    I’m looking for clarification on two WordPress Managed update questions.

    1. Package availability
      Has a WordPress Managed package containing the fix for CVE-2026-87902—WordPress 7.1.2, or an equivalent documented fix—been published?
      The latest entry I found in the Managed WordPress package-update thread (https://forum.cloudron.io/topic/2407/wordpress-managed-package-updates?page=2) was 3.20.2 / WordPress 7.1.1. If there’s a newer release or an existing discussion about this patch, a link would be appreciated.
    2. Automatic-update behavior
      The documentation explains how to disable automatic updates for an individual app, but I couldn’t find what happens to updates already in progress through the scheduling process.
      If that app’s automatic-update toggle is turned off, what happens to:
    • An available update displayed as pending;
    • An update already queued for execution;
    • An update already running?
      Is the setting checked again before a queued task starts, or does it only prevent future scheduling?
      Also, does Check for updates only refresh availability, with installation handled separately by the configured schedule, or can it initiate installation under the current automatic-update policy?
      I’m trying to understand the supported maintenance process, not bypass Cloudron’s managed updater. Thanks for any documentation links or clarification.
    1 Reply Last reply
    1
    • jamesJ
      jamesJ
      james
      Staff
      wrote last edited by
      #2

      Hello @milohiss

      @milohiss said:

      Has a WordPress Managed package containing the fix for CVE-2026-87902—WordPress 7.1.2, or an equivalent documented fix—been published?

      If the update is not listed in the forum and not visible for your WordPress, no the update has not yet been published.

      On your 2. questions, if automatic updates for an individual app is disabled:

      @milohiss said:

      updates already in progress through the scheduling process

      An app update that is already actively running will not be cancled.

      @milohiss said:

      An available update displayed as pending

      The update will be displayed in the dashboard, but will not auto update.

      @milohiss said:

      update already queued for execution

      If queued it should be executed.
      Adding, I understand queued as in 10x wordpress apps have been given the command to be updated.
      3x are actively updating the other 7x are queued and waiting.
      A difference would be sceduled updates.
      So if 10x wordpress instances have an update avilable and the next schedule is for e.g.: 18:00 o'clock.
      If automatic updates for these 10x wordpress are now disabled they should not be updated at 18:00 o'clock.

      @milohiss said:

      An update already running

      Same as above, already running updates should not be cancled

      M 1 Reply Last reply
      1
      • jamesJ james

        Hello @milohiss

        @milohiss said:

        Has a WordPress Managed package containing the fix for CVE-2026-87902—WordPress 7.1.2, or an equivalent documented fix—been published?

        If the update is not listed in the forum and not visible for your WordPress, no the update has not yet been published.

        On your 2. questions, if automatic updates for an individual app is disabled:

        @milohiss said:

        updates already in progress through the scheduling process

        An app update that is already actively running will not be cancled.

        @milohiss said:

        An available update displayed as pending

        The update will be displayed in the dashboard, but will not auto update.

        @milohiss said:

        update already queued for execution

        If queued it should be executed.
        Adding, I understand queued as in 10x wordpress apps have been given the command to be updated.
        3x are actively updating the other 7x are queued and waiting.
        A difference would be sceduled updates.
        So if 10x wordpress instances have an update avilable and the next schedule is for e.g.: 18:00 o'clock.
        If automatic updates for these 10x wordpress are now disabled they should not be updated at 18:00 o'clock.

        @milohiss said:

        An update already running

        Same as above, already running updates should not be cancled

        M
        M
        milohiss
        wrote last edited by
        #3

        @james

        Thanks for the earlier clarification. Our WordPress Managed app now offers package 3.20.3-1, showing WordPress 7.1.2, while the public announcement describes 3.20.3.

        What changed in the -1 revision? Does it introduce any runtime, dependency, migration or minimum-Cloudron-version changes beyond the documented WordPress 7.1.2 security update?

        1 Reply Last reply
        0
        • jamesJ
          jamesJ
          james
          Staff
          wrote last edited by james
          #4

          Hello @milohiss
          The @wordpress-managed version 3.20.3 had an issue where old installations did not set HTTPS=on correctly and 3.20.3-1 fixes this issue.
          From a SemVer standpoint 3.20.3-1 is lower than 3.20.3 so adding a changelog entry for 3.20.3-1 after 3.20.3 would be considered wrong.
          A long time ago we decided to use the $VERSION-X format as means for the Cloudron app store to directly offer the -X version instead of the $VERSION so the faulty version is skipped.
          Please apologize this confusion.

          1 Reply Last reply
          0

          Hello! It looks like you're interested in this conversation, but you don't have an account yet.

          Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

          With your input, this post could be even better 💗

          Register Login
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Don't have an account? Register

          • Login or register to search.
          • First post
            Last post
          0
          • Categories
          • Recent
          • Tags
          • Popular
          • Bookmarks
          • Search