Forum Replies Created

Viewing 6 replies - 1 through 6 (of 6 total)
  • Thread Starter htjoe38

    (@htjoe38)

    You say that —

    Gutenberg it self is fine in this regard

    and yet isn’t it Gutenberg it self that is generating the code that is being blocked ?
    i.e. it is Gutenburg Javascript / Ajax that is generating the Non-escaped POST data in the first place ?
    That would make it Gutenburg’s problem ?

    Thread Starter htjoe38

    (@htjoe38)

    Hi Maikuolan
    Long time no see — joe38 from the original zbblock forum.

    Unfortunately I have a dynamic IP so I can’t whitelist it. I could create a bypass as you suggest but …

    It would appear that others are having the same problem when using Sucuri security software.

    So it would make sense to me if the Gutenberg ajax/javascript sanitized it’s POST data before it gets to the server – i.e. at the client end of things, which would be in complete control of the Gutenburg Ajax. This must be better programming / ethos otherwise you are encouraging WordPress to accept non-escaped POST data as the norm and I’m sure that sooner or later the hackers will find a way to utilize this. You are just leaving the security door wide open.

    This sounds like the same problem I have as raised here.

    It would appear that Gutenberg has a security problem in not sanitizing it’s POST data.

    Hi @alignak

    Updated to 2.3.9 and the font files are now loading correctly.

    Thanks for you fast response.

    Joe

    I’m seeing the same thing.
    elusive.woff which is small graphics/fonts and should be loaded from the /themes/ is now being requested from the relative page path, is not found and returns 404 errors.

    This has only just started to happen with the update to v2.3.7 of the plugin. All had been working fine up to v2.3.7

    Disabling FVM restores everything to normal.

    Joe

    Hi orbetllc

    I too can’t register – it gives 500 error messages. For me it appears to be a problem with PHP 7.x
    What PHP are you running and have you recently updated your PHP?

    I have posted a support ticket seven days ago and am waiting for a response. In my post I have suggested an answer – which appears to work but I’m hoping the plugin author will confirm my suggestion.

    Joe38

    My Support post here

    • This reply was modified 6 years, 3 months ago by htjoe38.
Viewing 6 replies - 1 through 6 (of 6 total)