PluginProbe
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! / 3.7.2
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! v3.7.2
3.7.5 3.7.4 3.7.3 3.7.2 1-final 3.7.1 3.7.0 3.6.8 3.6.7 3.6.6 3.6.5 3.6.4 3.6.3 3.6.2 3.6.1 3.0.3 3.0.4 3.0.5 3.0.6 3.0.7 3.0.8 3.0.9 3.1.0 3.1.1 3.1.10 All 111 releases
← All changes | includes/Utils/Installer.php +6 -1 3.6.43.7.2 View file →
@@ -126,9 +126,14 @@
126 126 $install_status = install_plugin_install_status( $api );
127 127 $plugin['plugin_file'] = $install_status['file'];
128 128 }
129 129
130 - if ( !Helper::current_user_can( 'activate_plugins' ) && is_plugin_inactive( $file ) ) {
130 + // `$file` was never defined here — the plugin path lives in
131 + // $plugin['plugin_file'], and it is reassigned above when a fresh install
132 + // resolves a different one. The undefined name made is_plugin_inactive()
133 + // see null, which is never "active", so the guard silently collapsed to a
134 + // bare capability test. It failed closed, but it was not the check written.
135 + if ( !Helper::current_user_can( 'activate_plugins' ) && is_plugin_inactive( $plugin['plugin_file'] ) ) {
131 136 $response['code'] = 'invalid_requirements';
132 137 $response['message'] = __( 'Sorry, you do not have permission to activate a plugin.', 'templately' );
133 138 return $response;
134 139 }