Support » Plugin: Wordfence Security » Latest WordFence firewall update interfering with new members in membership site

  • Resolved danak

    (@danak)


    On Thursday my membership website had a notice from WordFence that its firewall needed updating. So I updated. Later that day, a new member joined and her confirming email from the website included the strange message below (most of it was in a pink box) – (She had not been added to the members area, but I was able to add her manually after she forwarded the email with her password and she was then able to access the members area. Not all new members would be as patient.) The membership software is MemberSonic and I have put in a support ticket there, but it does look like a WordFence firewall issue. How can I fix this in WordFence – or return it to the settings prior to the update? Here is WF message included in her email, below the usual welcome information —

    Your access to this site has been limited
    Your access to this service has been temporarily limited. Please try again in a few minutes. (HTTP response code 503)
    Reason: POST received with blank user-agent and referer
    Important note for site admins: If you are the administrator of this website note that your access has been limited because you broke one of the Wordfence firewall rules. The reason your access was limited is: “POST received with blank user-agent and referer”.

    If this is a false positive, meaning that your access to your own site has been limited incorrectly, then you will need to regain access to your site, go to the Wordfence “options” page, go to the section for Rate Limiting Rules and disable the rule that caused you to be blocked. For example, if you were blocked because it was detected that you are a fake Google crawler, then disable the rule that blocks fake google crawlers. Or if you were blocked because you were accessing your site too quickly, then increase the number of accesses allowed per minute.

    If you’re still having trouble, then simply disable the Wordfence firewall and you will still benefit from the other security features that Wordfence provides.

    If you are a site administrator and have been accidentally locked out, please enter your email in the box below and click “Send”. If the email address you enter belongs to a known site administrator or someone set to receive Wordfence alerts, we will send you an email to help you regain access. Please read this FAQ entry if this does not work.

    https://wordpress.org/plugins/wordfence/

Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Support wfalaa

    (@wfalaa)

    Hi danak,
    This request seems to be blocked because of this option “Block IP’s who send POST requests with blank User-Agent and Referer” under (Wordfence > Options => Other Options).

    Please go to (Wordfence > Live Traffic) and filter the traffic by “Blocked by Firewall”, you should be able to see these blocked requests and you can press “Whitelist param from Firewall” and this should whitelist these requests in the future.

    Let me know how it goes,
    Thanks.

    HI, wfalaa,

    Pleased to hear your suggestion is the same as another person’s on the membership plugin’s group. I have unchecked it. Apparently it checked that option during the WF firewall update earlier in the day, as it is not checked on other sites that had not been updated.

    I think it’s too long ago now for it to show up in the Live Traffic, but I will go there to whitelist any in the future.

    Next new member will tell me if this was the solution; will let you know.

    Thanks for your help,
    danak

    – no access through normal means possible sftp renamed plugin
    – email did not work
    – installed wordfence assistant- of course since i couldn’t log in, didn’t work
    – removed wordfence plugin altogether
    – all plugins deactivated
    – w.s.o.d
    – mysql backed up from database
    – I quit
    – removed wordpress subfolder entirely
    – switch to Drupal and joomla ; this is the 5 th time I am having this problem with wordpress.
    – Can you imagine this problem ? Not first time, it has happened 5 times in the past 6 years
    – plugins are wordpress’ death

    Wordfence is certainly a NO GO for my other blogs.
    all wordfence installations removed – there are better ways – and certainly less complicated – ones.

    Thanks for the mess. From Google this was my most visited page.

    africasiaeurocom

Viewing 3 replies - 1 through 3 (of 3 total)
  • The topic ‘Latest WordFence firewall update interfering with new members in membership site’ is closed to new replies.