auto-save failed — Non-escaped characters in POST
-
I started to create a new page, got as far as a heading and the auto-save failed.
The website security software — CIDRAM — was blocking Gutenberg because —Non-escaped characters in POST
or to put it another way it would appear that Gutenberg is not sanitizing the POST data.
I regularly see hackers trying to enter computer code via the Contact-us page, and it is either stopped by the Contact-us page sanitizing the POST data and/or the security software blocks it. This is a common attack vector, and if Gutenberg is not correctly sanitizing it’s POST data then Gutenberg could be a significant security risk.
Rather that reduce the website security I have disabled Gutenberg, until this is fixed.
- The topic ‘auto-save failed — Non-escaped characters in POST’ is closed to new replies.