[wp-trac] [WordPress Trac] #16778: wordpress is leaking user/blog information during wp_version_check()

WordPress Trac noreply at wordpress.org
Wed Dec 7 12:14:03 UTC 2016


#16778: wordpress is leaking user/blog information during wp_version_check()
----------------------------+-----------------------
 Reporter:  investici       |       Owner:
     Type:  enhancement     |      Status:  reopened
 Priority:  normal          |   Milestone:
Component:  Administration  |     Version:
 Severity:  minor           |  Resolution:
 Keywords:  has-patch       |     Focuses:
----------------------------+-----------------------

Comment (by robertheessels):

 This is absurd!

 Send sensitive private info, like number of users, without consent or
 clear warning is morally wrong, if not outright illegal in some countries.

 Why are plugins forced to only phone home when the user gives specific
 consent, while WordPress itself phones home very sensitive info?

 Absurd!

--
Ticket URL: <https://core.trac.wordpress.org/ticket/16778#comment:60>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list