@@ -466,6 +466,7 @@ SecRule REQUEST_FILENAME "@unconditionalMatch" \
466
466
ctl:ruleRemoveTargetById=931130;ARGS:_wp_http_referer,\
467
467
ctl:ruleRemoveTargetById=932150;ARGS:_wp_http_referer,\
468
468
ctl:ruleRemoveTargetById=932200;ARGS:_wp_http_referer,\
469
+ ctl:ruleRemoveTargetById=932235;ARGS:_wp_http_referer,\
469
470
ctl:ruleRemoveTargetById=932236;ARGS:_wp_http_referer,\
470
471
ctl:ruleRemoveTargetById=941100;ARGS:_wp_http_referer,\
471
472
ctl:ruleRemoveTargetById=942130;ARGS:_wp_http_referer,\
@@ -477,6 +478,7 @@ SecRule REQUEST_FILENAME "@unconditionalMatch" \
477
478
ctl:ruleRemoveTargetById=942432;ARGS:_wp_http_referer,\
478
479
ctl:ruleRemoveTargetById=942440;ARGS:_wp_http_referer,\
479
480
ctl:ruleRemoveTargetById=920230;ARGS:wp_http_referer,\
481
+ ctl:ruleRemoveTargetById=920273;ARGS:wp_http_referer,\
480
482
ctl:ruleRemoveTargetById=931130;ARGS:wp_http_referer,\
481
483
ctl:ruleRemoveTargetById=932150;ARGS:wp_http_referer,\
482
484
ctl:ruleRemoveTargetById=932200;ARGS:wp_http_referer,\
@@ -488,6 +490,7 @@ SecRule REQUEST_FILENAME "@unconditionalMatch" \
488
490
ctl:ruleRemoveTargetById=942230;ARGS:wp_http_referer,\
489
491
ctl:ruleRemoveTargetById=942260;ARGS:wp_http_referer,\
490
492
ctl:ruleRemoveTargetById=942431;ARGS:wp_http_referer,\
493
+ ctl:ruleRemoveTargetById=942432;ARGS:wp_http_referer,\
491
494
ctl:ruleRemoveTargetById=932236;ARGS:_wpnonce,\
492
495
ctl:ruleRemoveTargetById=942450;ARGS:_wpnonce,\
493
496
ver:'wordpress-rule-exclusions-plugin/1.0.1'"
@@ -624,6 +627,7 @@ SecRule REQUEST_FILENAME "@endsWith /wp-admin/user-new.php" \
624
627
ctl:ruleRemoveTargetByTag=OWASP_CRS;ARGS:pass2"
625
628
626
629
# The ID variable is used all over wordpress
630
+ # Managing users
627
631
SecRule REQUEST_FILENAME "@rx /wp-admin/(?:admin|admin-ajax|edit|users)\.php$" \
628
632
"id:9507601,\
629
633
phase:1,\
@@ -632,6 +636,8 @@ SecRule REQUEST_FILENAME "@rx /wp-admin/(?:admin|admin-ajax|edit|users)\.php$" \
632
636
nolog,\
633
637
ctl:ruleRemoveTargetById=932236;ARGS_NAMES:id,\
634
638
ctl:ruleRemoveTargetById=932236;ARGS_NAMES:ids,\
639
+ ctl:ruleRemoveTargetById=920273;ARGS_NAMES:users[0],\
640
+ ctl:ruleRemoveTargetById=942432;ARGS_NAMES:users[0],\
635
641
ver:'wordpress-rule-exclusions-plugin/1.0.1'"
636
642
637
643
#
0 commit comments