@@ -45,7 +45,7 @@ SecRule REQUEST_FILENAME "@endsWith /wp-login.php" \
45
45
nolog,\
46
46
ctl:ruleRemoveTargetById=932236;ARGS_NAMES:pwd,\
47
47
ctl:ruleRemoveTargetByTag=OWASP_CRS;ARGS:pwd,\
48
- ver:'wordpress-rule-exclusions-plugin/1.0.1 '"
48
+ ver:'wordpress-rule-exclusions-plugin/1.1.0 '"
49
49
50
50
# Redirect for wp-login/wp-admin
51
51
SecRule REQUEST_FILENAME "@rx /wp-(?:login|admin/admin-ajax)\.php$" \
@@ -59,7 +59,7 @@ SecRule REQUEST_FILENAME "@rx /wp-(?:login|admin/admin-ajax)\.php$" \
59
59
ctl:ruleRemoveTargetById=942430;ARGS:redirect_to,\
60
60
ctl:ruleRemoveTargetById=942431;ARGS:redirect_to,\
61
61
ctl:ruleRemoveTargetById=942432;ARGS:redirect_to,\
62
- ver:'wordpress-rule-exclusions-plugin/1.0.1 '"
62
+ ver:'wordpress-rule-exclusions-plugin/1.1.0 '"
63
63
64
64
# Reset password
65
65
SecRule REQUEST_FILENAME "@endsWith /wp-login.php" \
@@ -88,7 +88,7 @@ SecRule REQUEST_FILENAME "@endsWith /wp-admin/admin-ajax.php" \
88
88
nolog,\
89
89
ctl:ruleRemoveTargetById=932236;ARGS_NAMES:pwd,\
90
90
ctl:ruleRemoveTargetByTag=OWASP_CRS;ARGS:pwd,\
91
- ver:'wordpress-rule-exclusions-plugin/1.0.1 '"
91
+ ver:'wordpress-rule-exclusions-plugin/1.1.0 '"
92
92
93
93
#
94
94
# [ Comments ]
@@ -105,7 +105,7 @@ SecRule REQUEST_FILENAME "@endsWith /wp-comments-post.php" \
105
105
ctl:ruleRemoveTargetByTag=OWASP_CRS;ARGS:comment,\
106
106
ctl:ruleRemoveTargetByTag=OWASP_CRS;ARGS:email,\
107
107
ctl:ruleRemoveTargetByTag=OWASP_CRS;ARGS:url,\
108
- ver:'wordpress-rule-exclusions-plugin/1.0.1 '"
108
+ ver:'wordpress-rule-exclusions-plugin/1.1.0 '"
109
109
110
110
SecRule REQUEST_FILENAME "@endsWith /wp-admin/comment.php" \
111
111
"id:9507131,\
@@ -117,7 +117,7 @@ SecRule REQUEST_FILENAME "@endsWith /wp-admin/comment.php" \
117
117
ctl:ruleRemoveTargetByTag=attack-sqli;ARGS:newcomment_author_url,\
118
118
ctl:ruleRemoveTargetByTag=OWASP_CRS;ARGS:content,\
119
119
ctl:ruleRemoveTargetByTag=OWASP_CRS;ARGS:newcomment_author,\
120
- ver:'wordpress-rule-exclusions-plugin/1.0.1 '"
120
+ ver:'wordpress-rule-exclusions-plugin/1.1.0 '"
121
121
122
122
# Replying to a comment
123
123
SecRule REQUEST_FILENAME "@endsWith /wp-admin/admin-ajax.php" \
@@ -156,7 +156,7 @@ SecRule REQUEST_FILENAME "@rx /wp-json/wp/v[0-9]/global-styles/[0-9]+$" \
156
156
ctl:ruleRemoveTargetById=942431;ARGS,\
157
157
ctl:ruleRemoveTargetById=942432;ARGS,\
158
158
ctl:ruleRemoveTargetById=942440;ARGS,\
159
- ver:'wordpress-rule-exclusions-plugin/1.0.1 '"
159
+ ver:'wordpress-rule-exclusions-plugin/1.1.0 '"
160
160
161
161
# Gutenberg
162
162
SecRule REQUEST_FILENAME "@rx /wp-json/wp/v[0-9]+/(?:navigation|pages|posts|template-parts|templates)" \
@@ -167,7 +167,7 @@ SecRule REQUEST_FILENAME "@rx /wp-json/wp/v[0-9]+/(?:navigation|pages|posts|temp
167
167
nolog,\
168
168
ctl:ruleRemoveTargetByTag=OWASP_CRS;ARGS:content,\
169
169
ctl:ruleRemoveTargetByTag=OWASP_CRS;ARGS:json.content,\
170
- ver:'wordpress-rule-exclusions-plugin/1.0.1 '"
170
+ ver:'wordpress-rule-exclusions-plugin/1.1.0 '"
171
171
172
172
# Gutenberg via rest_route for sites without pretty permalinks
173
173
SecRule REQUEST_FILENAME "@endsWith /index.php" \
@@ -205,7 +205,7 @@ SecRule REQUEST_FILENAME "@rx /wp-json/wp/v[0-9]+/media" \
205
205
ctl:ruleRemoveById=200002,\
206
206
ctl:ruleRemoveById=200004,\
207
207
ctl:ruleRemoveTargetById=920120;FILES:file,\
208
- ver:'wordpress-rule-exclusions-plugin/1.0.1 '"
208
+ ver:'wordpress-rule-exclusions-plugin/1.1.0 '"
209
209
210
210
# Gutenberg upload image/media via rest_route for sites without pretty permalinks
211
211
SecRule REQUEST_FILENAME "@endsWith /index.php" \
@@ -388,7 +388,7 @@ SecRule REQUEST_FILENAME "@endsWith /wp-cron.php" \
388
388
nolog,\
389
389
ctl:ruleRemoveById=920180,\
390
390
ctl:ruleRemoveById=920300,\
391
- ver:'wordpress-rule-exclusions-plugin/1.0.1 '"
391
+ ver:'wordpress-rule-exclusions-plugin/1.1.0 '"
392
392
393
393
# Modifying widgets under Appearance --> Widgets
394
394
# Rules are disabled for all args because the paramater name keeps on changing
@@ -505,7 +505,7 @@ SecRule REQUEST_FILENAME "@unconditionalMatch" \
505
505
ctl:ruleRemoveTargetById=942440;ARGS:wp_http_referer,\
506
506
ctl:ruleRemoveTargetById=932236;ARGS:_wpnonce,\
507
507
ctl:ruleRemoveTargetById=942450;ARGS:_wpnonce,\
508
- ver:'wordpress-rule-exclusions-plugin/1.0.1 '"
508
+ ver:'wordpress-rule-exclusions-plugin/1.1.0 '"
509
509
510
510
511
511
# `_wp_original_http_referer` and `referredby` are used by the "Classic-Editor" plugin.
@@ -534,7 +534,7 @@ SecRule ARGS_NAMES "@rx ^_wp_original_http_referer|referredby$" \
534
534
ctl:ruleRemoveTargetById=920273;ARGS_NAMES:_wp_original_http_referer,\
535
535
ctl:ruleRemoveTargetById=920273;ARGS_NAMES:referredby,\
536
536
ctl:ruleRemoveTargetById=920273;REQUEST_BODY,\
537
- ver:'wordpress-rule-exclusions-plugin/1.0.1 '"
537
+ ver:'wordpress-rule-exclusions-plugin/1.1.0 '"
538
538
539
539
540
540
#
@@ -679,7 +679,7 @@ SecRule REQUEST_FILENAME "@rx /wp-admin/(?:admin|admin-ajax|edit|users)\.php$" \
679
679
ctl:ruleRemoveTargetById=932236;ARGS_NAMES:ids,\
680
680
ctl:ruleRemoveTargetById=920273;ARGS_NAMES:users[0],\
681
681
ctl:ruleRemoveTargetById=942432;ARGS_NAMES:users[0],\
682
- ver:'wordpress-rule-exclusions-plugin/1.0.1 '"
682
+ ver:'wordpress-rule-exclusions-plugin/1.1.0 '"
683
683
684
684
#
685
685
# [ Content editing ]
@@ -1003,7 +1003,7 @@ SecRule REQUEST_FILENAME "@endsWith /wp-admin/options-permalink.php" \
1003
1003
ctl:ruleRemoveTargetById=942431;ARGS:permalink_structure,\
1004
1004
ctl:ruleRemoveTargetById=942521;ARGS:permalink_structure,\
1005
1005
ctl:ruleRemoveTargetById=920272;REQUEST_BODY,\
1006
- ver:'wordpress-rule-exclusions-plugin/1.0.1 '"
1006
+ ver:'wordpress-rule-exclusions-plugin/1.1.0 '"
1007
1007
1008
1008
# Comments deny list and moderation list
1009
1009
SecRule REQUEST_FILENAME "@endsWith /wp-admin/options.php" \
@@ -1037,7 +1037,7 @@ SecRule REQUEST_FILENAME "@endsWith /wp-admin/edit.php" \
1037
1037
t:none,\
1038
1038
nolog,\
1039
1039
ctl:ruleRemoveTargetByTag=OWASP_CRS;ARGS:s,\
1040
- ver:'wordpress-rule-exclusions-plugin/1.0.1 '"
1040
+ ver:'wordpress-rule-exclusions-plugin/1.1.0 '"
1041
1041
1042
1042
1043
1043
#
@@ -1089,7 +1089,7 @@ SecRule REQUEST_FILENAME "@rx /wp-admin/load-(?:scripts|styles)\.php$" \
1089
1089
ctl:ruleRemoveTargetById=942431;ARGS:load[chunk_2],\
1090
1090
ctl:ruleRemoveTargetById=942432;ARGS:load[chunk_2],\
1091
1091
ctl:ruleRemoveTargetById=920100;REQUEST_LINE,\
1092
- ver:'wordpress-rule-exclusions-plugin/1.0.1 '"
1092
+ ver:'wordpress-rule-exclusions-plugin/1.1.0 '"
1093
1093
1094
1094
# Wordpress Site Health
1095
1095
# The wordpress site health page makes use of embedded SQL/PHP
0 commit comments