Description
Themes created by Create Block Theme can be silently overwritten by an unrelated theme from the WordPress.org Theme Directory when both themes have the same slug.
This came up during a Create Block Theme workshop. A participant cloned the Bluehost Blueprint theme and named the clone Cozy Cafe. Create Block Theme generated the slug cozy-cafe and activated the new theme successfully. A different theme already exists in the WordPress.org Theme Directory with that slug. WordPress subsequently treated the workshop participant's custom theme as the directory theme and replaced it with the unrelated Cozy Cafe theme during an update.
From the participant's perspective, the theme they had just created suddenly changed into a completely different theme, with no indication that choosing the name could put their work at risk.
WordPress 6.1 introduced the Update URI theme header specifically to prevent custom themes from being overwritten when their slug happens to match a WordPress.org theme:
https://make.wordpress.org/core/2022/10/06/introducing-update-uri-theme-header-in-wordpress-6-1/
Steps to reproduce
- Activate a block theme, such as Bluehost Blueprint.
- Use Create Block Theme to clone it.
- Name the new theme
Cozy Cafe.
- Confirm that the generated theme directory and text domain are
cozy-cafe.
- Allow WordPress or the hosting provider to check for and apply theme updates.
Actual result
WordPress detects the unrelated cozy-cafe theme from WordPress.org as an update. Applying that update replaces the custom theme's files and can destroy the user's work.
The local file_exists() check only protects against an existing directory at creation time. It does not protect the generated theme from a later WordPress.org update.
Expected result
Every newly created theme produced by Create Block Theme should be protected from unrelated WordPress.org updates by default.
Proposed solution
Add the following header to every newly generated clone, blank theme, and child theme:
This should apply to themes newly created by CBT. Existing Update URI values on source or existing themes should be preserved when CBT saves, edits, or exports them, so intentional third-party update integrations are not disabled.
An additional warning when a generated slug already exists in the WordPress.org Theme Directory could be useful, but the generated Update URI: false header should provide the underlying protection even when a collision appears later.
Environment
- Create Block Theme 2.10.1/current
trunk
- WordPress 6.8 or later
Description
Themes created by Create Block Theme can be silently overwritten by an unrelated theme from the WordPress.org Theme Directory when both themes have the same slug.
This came up during a Create Block Theme workshop. A participant cloned the Bluehost Blueprint theme and named the clone Cozy Cafe. Create Block Theme generated the slug
cozy-cafeand activated the new theme successfully. A different theme already exists in the WordPress.org Theme Directory with that slug. WordPress subsequently treated the workshop participant's custom theme as the directory theme and replaced it with the unrelated Cozy Cafe theme during an update.From the participant's perspective, the theme they had just created suddenly changed into a completely different theme, with no indication that choosing the name could put their work at risk.
WordPress 6.1 introduced the
Update URItheme header specifically to prevent custom themes from being overwritten when their slug happens to match a WordPress.org theme:https://make.wordpress.org/core/2022/10/06/introducing-update-uri-theme-header-in-wordpress-6-1/
Steps to reproduce
Cozy Cafe.cozy-cafe.Actual result
WordPress detects the unrelated
cozy-cafetheme from WordPress.org as an update. Applying that update replaces the custom theme's files and can destroy the user's work.The local
file_exists()check only protects against an existing directory at creation time. It does not protect the generated theme from a later WordPress.org update.Expected result
Every newly created theme produced by Create Block Theme should be protected from unrelated WordPress.org updates by default.
Proposed solution
Add the following header to every newly generated clone, blank theme, and child theme:
This should apply to themes newly created by CBT. Existing
Update URIvalues on source or existing themes should be preserved when CBT saves, edits, or exports them, so intentional third-party update integrations are not disabled.An additional warning when a generated slug already exists in the WordPress.org Theme Directory could be useful, but the generated
Update URI: falseheader should provide the underlying protection even when a collision appears later.Environment
trunk