Modsecurity crs4 rule exclusions for WordPress Rest API?
-
I am running an Ubuntu 20.04 LEMP Server with Modsecurity installed. I am using the brand new CRS4 for my ruleset. When Modsecurity is off in my wordpress health page, I get no errors. However, after turning on Modsecurity in my WP health page, I get the following errors on my WP health screen:
The REST API is one way that WordPress and other applications communicate with the server. For example, the block editor screen relies on the REST API to display and save your posts and pages. When testing the REST API, an unexpected result was returned: REST API Endpoint: https://www.mcmo.is/wp-json/wp/v2/types/post?context=edit REST API Response: (403) Forbidden
I’m finding nothing in the modsec logs. How can I go about finding and setting the proper rule exclusions for CRS4 in Modsecurity? Please help if you are knowledgable about Modsecurity and rule exclusions.
The page I need help with: [log in to see the link]
Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)
- The topic ‘Modsecurity crs4 rule exclusions for WordPress Rest API?’ is closed to new replies.