<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[WordPress Managed: 7.1.2 security-fix package and automatic-update behavior]]></title><description><![CDATA[<p dir="auto">I’m looking for clarification on two WordPress Managed update questions.</p>
<ol>
<li>Package availability<br />
Has a WordPress Managed package containing the fix for CVE-2026-87902—WordPress 7.1.2, or an equivalent documented fix—been published?<br />
The latest entry I found in the Managed WordPress package-update thread (<a href="https://forum.cloudron.io/topic/2407/wordpress-managed-package-updates?page=2">https://forum.cloudron.io/topic/2407/wordpress-managed-package-updates?page=2</a>) was 3.20.2 / WordPress 7.1.1. If there’s a newer release or an existing discussion about this patch, a link would be appreciated.</li>
<li>Automatic-update behavior<br />
The documentation explains how to disable automatic updates for an individual app, but I couldn’t find what happens to updates already in progress through the scheduling process.<br />
If that app’s automatic-update toggle is turned off, what happens to:</li>
</ol>
<ul>
<li>An available update displayed as pending;</li>
<li>An update already queued for execution;</li>
<li>An update already running?<br />
Is the setting checked again before a queued task starts, or does it only prevent future scheduling?<br />
Also, does Check for updates only refresh availability, with installation handled separately by the configured schedule, or can it initiate installation under the current automatic-update policy?<br />
I’m trying to understand the supported maintenance process, not bypass Cloudron’s managed updater. Thanks for any documentation links or clarification.</li>
</ul>
]]></description><link>https://forum.cloudron.io/topic/15998/wordpress-managed-7.1.2-security-fix-package-and-automatic-update-behavior</link><generator>RSS for Node</generator><lastBuildDate>Wed, 30 Sep 2026 14:20:08 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/15998.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 23 Sep 2026 06:17:24 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to WordPress Managed: 7.1.2 security-fix package and automatic-update behavior on Thu, 24 Sep 2026 07:16:47 GMT]]></title><description><![CDATA[<p dir="auto">Hello <a class="plugin-mentions-user plugin-mentions-a" href="/user/milohiss" aria-label="Profile: milohiss">@<bdi>milohiss</bdi></a><br />
The <a class="plugin-mentions-category plugin-mentions-a" href="/category/12/wordpress-managed" aria-label="Profile: wordpress-managed">@<bdi>wordpress-managed</bdi></a> version <code>3.20.3</code> had an issue where old installations did not set <code>HTTPS=on</code> correctly and <code>3.20.3-1</code> fixes this issue.<br />
From a SemVer standpoint <code>3.20.3-1</code> is lower than <code>3.20.3</code> so adding a changelog entry for <code>3.20.3-1</code> after <code>3.20.3</code> would be considered wrong.<br />
A long time ago we decided to use the <code>$VERSION-X</code> format as means for the Cloudron app store to directly offer the <code>-X</code> version instead of the <code>$VERSION</code> so the faulty version is skipped.<br />
Please apologize this confusion.</p>
]]></description><link>https://forum.cloudron.io/post/129926</link><guid isPermaLink="true">https://forum.cloudron.io/post/129926</guid><dc:creator><![CDATA[james]]></dc:creator><pubDate>Thu, 24 Sep 2026 07:16:47 GMT</pubDate></item><item><title><![CDATA[Reply to WordPress Managed: 7.1.2 security-fix package and automatic-update behavior on Wed, 23 Sep 2026 17:37:53 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/james" aria-label="Profile: james">@<bdi>james</bdi></a></p>
<p dir="auto">Thanks for the earlier clarification. Our WordPress Managed app now offers package 3.20.3-1, showing WordPress 7.1.2, while the public announcement describes 3.20.3.</p>
<p dir="auto">What changed in the -1 revision? Does it introduce any runtime, dependency, migration or minimum-Cloudron-version changes beyond the documented WordPress 7.1.2 security update?</p>
]]></description><link>https://forum.cloudron.io/post/129923</link><guid isPermaLink="true">https://forum.cloudron.io/post/129923</guid><dc:creator><![CDATA[milohiss]]></dc:creator><pubDate>Wed, 23 Sep 2026 17:37:53 GMT</pubDate></item><item><title><![CDATA[Reply to WordPress Managed: 7.1.2 security-fix package and automatic-update behavior on Wed, 23 Sep 2026 10:20:51 GMT]]></title><description><![CDATA[<p dir="auto">Hello <a class="plugin-mentions-user plugin-mentions-a" href="/user/milohiss" aria-label="Profile: milohiss">@<bdi>milohiss</bdi></a></p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/milohiss" aria-label="Profile: milohiss">@<bdi>milohiss</bdi></a> <a href="/post/129871">said</a>:</p>
<p dir="auto">Has a WordPress Managed package containing the fix for CVE-2026-87902—WordPress 7.1.2, or an equivalent documented fix—been published?</p>
</blockquote>
<p dir="auto">If the update is not listed in the forum and not visible for your WordPress, no the update has not yet been published.</p>
<p dir="auto">On your 2. questions, if automatic updates for an individual app is disabled:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/milohiss" aria-label="Profile: milohiss">@<bdi>milohiss</bdi></a> <a href="/post/129871">said</a>:</p>
<p dir="auto">updates already in progress through the scheduling process</p>
</blockquote>
<p dir="auto">An app update that is already actively running will not be cancled.</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/milohiss" aria-label="Profile: milohiss">@<bdi>milohiss</bdi></a> <a href="/post/129871">said</a>:</p>
<p dir="auto">An available update displayed as pending</p>
</blockquote>
<p dir="auto">The update will be displayed in the dashboard, but will not auto update.</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/milohiss" aria-label="Profile: milohiss">@<bdi>milohiss</bdi></a> <a href="/post/129871">said</a>:</p>
<p dir="auto">update already queued for execution</p>
</blockquote>
<p dir="auto">If queued it should be executed.<br />
Adding, I understand queued as in 10x wordpress apps have been given the command to be updated.<br />
3x are actively updating the other 7x are queued and waiting.<br />
A difference would be sceduled updates.<br />
So if 10x wordpress instances have an update avilable and the next schedule is for e.g.: 18:00 o'clock.<br />
If automatic updates for these 10x wordpress are now disabled they should not be updated at 18:00 o'clock.</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/milohiss" aria-label="Profile: milohiss">@<bdi>milohiss</bdi></a> <a href="/post/129871">said</a>:</p>
<p dir="auto">An update already running</p>
</blockquote>
<p dir="auto">Same as above, already running updates should not be cancled</p>
]]></description><link>https://forum.cloudron.io/post/129893</link><guid isPermaLink="true">https://forum.cloudron.io/post/129893</guid><dc:creator><![CDATA[james]]></dc:creator><pubDate>Wed, 23 Sep 2026 10:20:51 GMT</pubDate></item></channel></rss>