• Resolved Starhorsepax2

    (@starhorsepax2)


    I keep having the widgets blocked by Wordfence. It’s really aggravating because even though I whitelist it the problem keeps returning. Both Wordfence and Page Builder/Widgets are VERY popular. Please find a way to fix this conflict. I’ve also asked them about it but I think whenever they update it updates the Whitelist and removes it. Why does it see your plugin as a security issue?

    This is the message minus the domain name:

    was blocked by firewall for XSS: Cross Site Scripting in POST body: panels_data=%7B%22widgets%22%3A%5B%7B%22image%22%3A679%2C%22image_fallback%22%3A%22%22%2C%22size%22%3A%22full%22… a

    wp-admin/admin-ajax.php?_panelsnonce=8bb368d675

Viewing 1 replies (of 1 total)
  • Plugin Contributor alexgso

    (@alexgso)

    Hi starhorsepax2,

    Wordfence, for whatever reason, incorrectly flags certain widgets (such as the SiteOrigin Button widget). Unfortunately, this sort of flagging isn’t something we’re able to fix as it’s happening as a result of how Wordfence scans for potential security issues. It’s a false positive (meaning it’s not an issue) but there’s nothing we can specifically do on our end that would prevent Wordfence from flagging the request.

    If whitelisting this doesn’t help, you should put the Wordfence Firewall into Learning Mode and replicate what you’ve what was previously getting blocked a few times. This will allow for Wordfence to account for it and prevent it from flagging it again.

Viewing 1 replies (of 1 total)

The topic ‘wordfence conflict HELP’ is closed to new replies.