Hi @didier59450,
Thanks for reporting this. This is related to:
What’s going on: after the wp2shell issue involving the core REST batch endpoint, some hosts/WAFs (Imunify360 included) added emergency rules that block /wp-json/batch/v1. Kadence Security’s settings screens use that core batch endpoint to save, so when the WAF returns a 403 or HTML block page instead of JSON, WordPress shows that error.
We’ve already escalated a resilience improvement to our developers for hosts that keep a hard block on batch/v1. In the meantime, the workaround is asking your host to allow authenticated admin requests to /wp-json/batch/v1 (or relax the emergency batch rule) once WordPress is on a patched release (7.0.2+, 6.9.5+, or 6.8.6+).
I’ll circle back here when I have more news on the escalation.
Thanks again!