URL Parameters ending in =
-
Better WP Security, with blocking bad URL phrases enabled, blocks parameters ending in an equal sign (=).
Better WP Security has a line like this
RewriteCond %{QUERY_STRING} ^.*(\[|\]|\(|\)|<|>|ê|"|;|\?|\*|=$).* [NC,OR]
I removed |=$, which blocks parameters ending with equals, like
/wp-admin/plugins.php?deactivate=true&plugin_status=all&paged=1&s=
That comes from a link like
/wp-admin/plugins.php?action=activate&plugin=types%2Fwpcf.php&plugin_status=all&paged=1&s&_wpnonce=e7f30a0090
or like
/wp-admin/plugins.php?action=deactivate&plugin=types%2Fwpcf.php&plugin_status=all&paged=1&s&_wpnonce=ae1c567616
Suggestion to all plugin writers: specify &s=1 instead of &s (parameters should always have a value).
- The topic ‘URL Parameters ending in =’ is closed to new replies.