• Resolved Alcohemy

    (@alcohemy)


    Since I have installed iThemes Security people that pay to join my WishList Member (WLM) membership site can’t complete their registration process. After payment they are automatically taken to my sites registration page to complete their details and choose a username and password. When they submit this form the get my HostGator server’s 403 Access denied page instead of going to the Member’s home page. WP and WLM show the registration process as ‘Incomplete’, so it appears the form they submit is being blocked fro getting through to WP or WLM plugin.

    The complete registration process works fine when I deactivate iThemes Security.
    Is this a settings issue in iTS or can someone suggest what the issue might be please?

    https://wordpress.org/plugins/better-wp-security/

Viewing 7 replies - 1 through 7 (of 7 total)
  • Hey Alcohemy,

    If you have them enabled, could you try disabling the “Suspicious Query Strings” and/or “Filter Long URL Strings” features and see if that helps?

    Please let me know!

    Thanks,

    Gerroald

    Thread Starter Alcohemy

    (@alcohemy)

    Thanks Gerroald. I disabled both those features and a test purchase processed the payment and registration process fine, giving access to the membership area as expected.

    I haven’t yet done a test on two features separately to see which one was the problem, as I wanted to get the registration working properly as quickly as possible. (Maybe they both had an effect?) I will do this and let you know with a reply to this thread.

    As you can see there are some very long strings that get set during the registration process:
    http://alcohemy.com/index.php?/register/continue&e=admin%40worldhealinghands.com&h=c234e704663ee4d136839c340b4fecd7

    https://www.mcssl.com/Portal/Login.aspx?mid=7AC1551B-BA00-4414-9B07-300E3839C393&acid=305dfcba-0dfb-4956-be60-67e351d61917

    Thanks very much for your very prompt advice.
    David

    Hey David,

    Thanks for the update!

    Gerroald

    Thread Starter Alcohemy

    (@alcohemy)

    Hi Gerroald

    I enabled the ‘Filter Long URL Strings’, while leaving the ‘Filter Suspicious Query Strings In URL’ disabled and a new test purchase and registration completed fine. This means to me it was just the later that was causing the registration to fail completion.

    I take it this isn’t a big risk leaving this Suspicious Query feature disabled?

    Thanks for helping me resolve this. I’m glad I can still use 99.9% of the iTS features.

    Regards, David

    Hey David,

    Thanks for the update. There’s no harm in not having the feature active. All of the features aren’t going to be appropriate for all WordPress/server environments. The idea is to enable as many as your environment will allow.

    Thanks,

    Gerroald

    Dharmaraj

    (@dharmarajiyer)

    Hi Gerroald and David,

    I have been experiencing the same conflict with WishList Member and iThemes Security. This thread was just what I needed. To fully fix my problem, I needed to uncheck both ‘Filter Suspicious Query Strings In URL’ and ‘Filter Long URL Strings’.

    The first feature (when checked) was causing 403 errors. The second feature (when checked) caused a White Screen of Death with no error messages (even with WP_DEBUG enabled). I noticed the URL request generated by WishList Member was really long.

    Thanks for guiding me in the right direction,
    Dharmaraj

    Thread Starter Alcohemy

    (@alcohemy)

    Hi Dharmaraj

    Yes the WLM registration URL is very long, though it wasn’t causing issues with my iThemes Security. The registration process is working OK for me with that ‘Filter Long URL Srings’ enabled.

    As Gerroald says, it isn’t critical to have either of these disabled. Glad this thread helped. I tried to Title it to be specific for others 🙂

Viewing 7 replies - 1 through 7 (of 7 total)
  • The topic ‘Conflict with WishList Member causing 403 access error’ is closed to new replies.