• So anyone can upgrade the db? Shouldn’t that occur during update process or after the auto update and the admin has authenticated? Allowing anyone that stumbles upon /wp-admin/ to click the upgrade database button without authentication seems…
    #hopefullygoodsamaritan

Viewing 1 replies (of 1 total)
  • Moderator James Huff

    (@macmanx)

    It actually doesn’t do anything if the database is already updated, which it should be anyway, because you can’t access the Dashboard after upgrading without doing that, kind of like how the install.php file won’t do anything if you’re already installed.

    Regardless though, even if you haven’t accessed your Dashboard in days since the upgrade, the worst thing (and the only thing) running upgrade.php can do is upgrade your database to the current version’s schema. Hardly nefarious. ??

Viewing 1 replies (of 1 total)
  • The topic ‘Upgrade database?’ is closed to new replies.