False positive using Events Made Easy Plugin
-
I recently installed WF on a site using Events Made Easy. Now there are 403 errors every time a client tries to book an event. (WF ver. 6.1.14)
On the traffic page in WF, it shows the following entry “blocked by firewall for XSS: Cross Site Scripting in POST body: eme_message. . .” each time someone has tried to book an event.
I’ve had to disable XSS checking in the firewall in order to keep the site operational.
Is there a way to whitelist the entire /events/ directory? Or some other way to avoid having the confirmation of booking page show only a “403 Forbidden” instead of the booking confirmation without entirely disabling XSS checking?
Thanks!
- The topic ‘False positive using Events Made Easy Plugin’ is closed to new replies.