Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Starter plan: Plugins are allowed to be installed #101084

Open
niranjan-uma-shankar opened this issue Mar 10, 2025 · 6 comments
Open

Starter plan: Plugins are allowed to be installed #101084

niranjan-uma-shankar opened this issue Mar 10, 2025 · 6 comments
Labels
[Experiment] AI labels added [Feature] Astra Pro [Feature Group] Plugins [Feature] Plugin Management Needs triage Ticket needs to be triaged [Pri] Normal Schedule for the next available opportuinity. [Status] Auto-allocated [Type] Bug When a feature is broken and / or not performing as intended

Comments

@niranjan-uma-shankar
Copy link
Contributor

niranjan-uma-shankar commented Mar 10, 2025

Context and steps to reproduce

Reported originally in: p58i-jnK-p2#comment-67000

On a Starter plan site, I was able to install a plugin, and this should not be allowed. The plan is a low cost $5/mo plan and does not support plugins, as confirmed in p58i-jnK-p2#comment-67060. This bug is opening a backdoor for a cheap atomic plan.

Steps to repro:

  1. On one of your accounts, add a Starter plan by following 37336-pb
  2. Go to the plugin marketplace and add Astra Pro plugin.
  3. Notice that you are able to add the plugin and take your site atomic without requiring an upgrade to Business

p58i-jnK-p2#comment-67000 has the blog RC for the site that went atomic on a Starter plan.

Site owner impact

Fewer than 20% of the total website/platform users

Severity

Major

What other impact(s) does this issue have?

No response

If a workaround is available, please outline it here.

No response

Platform

No response

Copy link

OpenAI suggested the following labels for this issue:

  • [Feature Group] Plugins: The issue directly concerns the installation of plugins, which is a core functionality governed by plugin management.
  • [Feature] Astra Pro: The specific plugin mentioned in the issue is Astra Pro, which is being improperly installed on a Starter plan.
  • [Feature] Plugin Management: The issue highlights a problem with how plugins are managed in relation to different WordPress plans.

@supernovia
Copy link
Contributor

📌 REPRODUCTION RESULTS

  • Tested – Could Not Replicate / Uncertain

📌 FINDINGS/SCREENSHOTS/VIDEO
Could't add starter; steps unclear

add a Starter plan by following 37336-pb/

📌 ACTIONS

  • Requested author feedback

📌 Message to Author
@daledupreez can you clarify the steps to add a Starter plan? I wasn't able to find it in the list, and the link you shared isn't linking for me.

@supernovia supernovia moved this from Needs Triage to In Triage in Automattic Prioritization: The One Board ™ Mar 10, 2025
@niranjan-uma-shankar
Copy link
Contributor Author

@daledupreez can you clarify the steps to add a Starter plan? I wasn't able to find it in the list, and the link you shared isn't linking for me.

@supernovia I assume you meant to tag me. Can you check if 37336-pb is linking for you? This is a pastebin shorthand which you can find in PCYsg-5Xx-p2

@supernovia
Copy link
Contributor

Oops! You're right! And the link works now; it didn't earlier. Thank you!

@supernovia
Copy link
Contributor

📌 REPRODUCTION RESULTS

  • Tested on Simple – Replicated

📌 FINDINGS/SCREENSHOTS/VIDEO

  • I confirmed that free plugins asked me to upgrade
  • I was also prompted to activate hosting features
  • BUT I was able to "purchase and activate" premium plugins from the marketplace and shouldn't have been
  • I also noticed when I go to /wp-admin/plugins.php I'm blocked from that

Sorry, you are not allowed to access this page.

📌 ACTIONS

  • Triaged
  • Assigned to @Automattic/bespin

@supernovia supernovia moved this from In Triage to Triaged in Automattic Prioritization: The One Board ™ Mar 11, 2025
@niranjan-uma-shankar
Copy link
Contributor Author

niranjan-uma-shankar commented Mar 12, 2025

@mreishus Is this related to your work in https://github.com/Automattic/wpcomsh/pull/1010? The PR talks about exposing the feature to proxied connections, but I am able to reproduce the issue on unproxied connection too.

Image

Site: niranjanwpcomtest1120325t1.wordpress.com

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
[Experiment] AI labels added [Feature] Astra Pro [Feature Group] Plugins [Feature] Plugin Management Needs triage Ticket needs to be triaged [Pri] Normal Schedule for the next available opportuinity. [Status] Auto-allocated [Type] Bug When a feature is broken and / or not performing as intended
Projects
Development

No branches or pull requests

3 participants