This prevents a situation where the actual admin logs in, their attention is taken away from the computer, and someone sits at their chair and does awful things with the computer.
If that's the case, no-one told the `sudo` command...
Maybe you already saw this but I see they also made the same security/ease of use tradeoff for the (non-buggy) locks in the other preference panes. After unlocking, it stays unlocked for a period of time while you are in preferences, even if you visit different areas within preferences and come back.
Nobody said, "We want to lower the security level of this feature, so let's keep the password prompt but allow any input to the password prompt."
[0] https://askubuntu.com/questions/636092/how-to-get-sudo-to-pr...
Disabling/enabling automatic updates
I fail to see how automatic updates would be "awful".
For example you could let your kid use your Mac, but you don't want them spending your money via your app-store linked credit card. If they have access to the App Store Preferences panel they can disable the requirement and do so.
Also this wasn't possible on Sierra.
In this case, any credentials work, meaning that if a "guest" user (semi-trusted by the account owner, obviously using the owner's credentials. ) were attempting to change these settings, they could bypass the prompt with a bogus password instead of the alternative which requires the guest to ask the owner to enter their password.