• Resolved lgabercrombie

    (@lgabercrombie)


    I get a 412 Error when I attempt to save the settings on the Email Users page in the Settings menu.
    It also shows a red box at the top:

    “It looks like you have an old version of the plugin activated. Please deactivate the plugin and activate it again to complete the installation of the new version.

    Installed Version: 4.5.2
    Current Version: 4.5.5

    The Plugins page shows that I have version 4.5.5 installed.

    http://wordpress.org/plugins/email-users/

Viewing 10 replies - 1 through 10 (of 10 total)
  • Plugin Author Mike Walsh

    (@mpwalsh8)

    If you go back to the settings page again do you get the same error? A 412 error code sounds like your web server hiccuped, I’ve never encountered it before.

    Thread Starter lgabercrombie

    (@lgabercrombie)

    Thread Starter lgabercrombie

    (@lgabercrombie)

    Yes, it is completely repeatable. I have tried deactivating and reactivating the plug-in several times, which got rid of the “old version” message, but the “412 Error” persists. Also tried with Firefox, Chrome and IE browsers.

    The full text of the error message is:
    ——————–
    412 Error

    Your request got filtered out due to possible security issues.

    One or more things in your request were suspicious (defective request header, invalid cookies, bad parameters)

    If you think you did nothing wrong:

    try again with a different browser
    avoid any evil characters inside the request url

    If you are the owner of the website, you can consider revising the rules of the mod_security module or turning it off from your Web Hosting Control Panel.

    Plugin Author Mike Walsh

    (@mpwalsh8)

    Mod_Security can be a royal PITA. I am not sure how to replicate it or what Mod_Security isn’t happy about. Is there anything logged in your Web Hosting Control Panel?

    Plugin Author Mike Walsh

    (@mpwalsh8)

    To be clear, every time you visit the Email Users settings page you get a 412 error or does it only happen when you try to save the settings?

    The warning message would have nothing to do with it, it is just HTML content.

    Thread Starter lgabercrombie

    (@lgabercrombie)

    It only happens when I try to Save Settings.

    I turned on error logging in my Web Hosting Control Panel, tried Saving again, and got the following error:

    [Tue Oct 08 23:50:17 2013] [error] [client 50.174.45.26] File does not exist: /services/users/f794cd92-f260-4a95-9cca-85cd7bcd778a/stillwatr/www/stillwaterclub.org/wordpress/wp-content/themes/atahualpa3710/images/favicon/swc-favicon.ico
    [Tue Oct 08 23:50:17 2013] [error] [client 50.174.45.26] File does not exist: /services/users/f794cd92-f260-4a95-9cca-85cd7bcd778a/stillwatr/www/stillwaterclub.org/wordpress/wp-content/themes/atahualpa3710/images/favicon/swc-favicon.ico
    [Tue Oct 08 23:50:47 2013] [error] [client 50.174.45.26] ModSecurity: 50.174.45.26 Access denied with code 412 (phase 2). detected SQLi using libinjection fingerprint ‘sonos’ at ARGS:mailusers_default_subject [file "/services/mod_security-rules/11_asl_adv_rules.conf"] [line "67"] [id "341245"] [rev "6"] [msg "Atomicorp.com WAF Rules: Possible SQL injection attack (detectSQLi)"] [data "sonos"] [severity "CRITICAL"] [uri " [hostname "stillwaterclub.org"]"]/wordpress/wp-admin/options.php

    Plugin Author Mike Walsh

    (@mpwalsh8)

    ModSecurity doesn’t like the default subject string which has percent signs in it which also happen to be wildcard characters in SQL. It appears that your ModSecurity thinks the default subject is an attemped SQL injection. This is the default subject:

    [%BLOG_NAME%] A post of interest: "%POST_TITLE%"

    As a test, take all of the percent characters (%) out, I bet the warning goes away.

    Thread Starter lgabercrombie

    (@lgabercrombie)

    Removed all the “%” characters from the Default Subject line, and the error went away when I save the settings.

    Plugin Author Mike Walsh

    (@mpwalsh8)

    That is exactly what I would have expected. Unfortunately there isn’t much I can do about your server configuration thinking the keyword substitution is a potential SQL injection. You may want to check with your hosting provider and see if they have any suggestions for this sort of issue.

    Plugin Author Mike Walsh

    (@mpwalsh8)

    Marking resolved.

Viewing 10 replies - 1 through 10 (of 10 total)
  • The topic ‘Unable to Save in Email Users in Settings menu’ is closed to new replies.