{"id":19030142,"date":"2026-09-26T17:36:52","date_gmt":"2026-09-26T17:36:52","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/borlabs-cookie-save-blocked-as-xss-in-fallbackcode\/"},"modified":"2026-09-26T17:36:52","modified_gmt":"2026-09-26T17:36:52","slug":"borlabs-cookie-save-blocked-as-xss-in-fallbackcode","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/borlabs-cookie-save-blocked-as-xss-in-fallbackcode\/","title":{"rendered":"Borlabs Cookie save blocked as XSS in fallbackCode"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Hello Wordfence team,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An authenticated save of a Borlabs Cookie Google Analytics service was blocked on 23 September 2026 at 18:38:09 UTC with HTTP 403. The recorded Wordfence reason is \u201cXSS: Cross Site Scripting in POST body: fallbackCode\u201d. The target was the regular \/wp-admin\/admin.php Borlabs service editor. The historical full POST payload and a numeric rule ID were not preserved. We have not repeated a production write merely to reproduce the block.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Recorded versions on 24 September: Wordfence 9.0.1, Borlabs Cookie 3.4.4, WordPress 7.1.2, PHP 8.3.33. These are observed installation versions, not a claim about current releases. WAF is Enabled and Protecting with Basic WordPress Protection and Community rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On 26 September at 15:52 UTC, a manual rules refresh returned \u201cRules updated\u201d successfully. Live Traffic filtered by URL contains borlabs-cookie-services, with All Hits and no date filter, showed no matching retained requests. Neither observation confirms a fix for the historical block.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two older exceptions already exist for request.body[optInCode] and request.body[optOutCode] on \/wp-admin\/admin.php, listed as added via the false positive dialog on 5 September. They were not added or changed for this investigation. No fallbackCode exception is listed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Borlabs referred the Wordfence-specific question to your team. The separate consent-configuration question remains with Borlabs. We request a supported diagnosis:<\/p>\n\n\n\n<ol>\n<li>What minimum read-only evidence and rule identifier do you need, and how can we obtain them through the normal plugin interface?<\/li>\n\n\n\n<li>Is there a secure non-public channel for a limited sanitized code sample if required? We will not post credentials, tokens, full logs or customer data here.<\/li>\n\n\n\n<li>Is a rule or compatibility correction available without adding an exception, using Learning Mode, disabling a rule, obfuscating code or bypassing the normal save route?<\/li>\n\n\n\n<li>How should the necessity of the two existing exceptions be assessed without changing production protection first?<\/li>\n\n\n\n<li>Before today&#8217;s successful manual refresh, the next scheduled rule check was displayed as 30 September 2026, 14:20 UTC. Which limited diagnostic confirms whether scheduling is functioning correctly?<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Extended Protection is a separate pending hardening task requiring configuration-file backups and an independent recovery path. We do not assume that enabling it would resolve this POST block. Thank you.<\/p>\n","protected":false},"template":"","class_list":["post-19030142","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19030142","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19030142\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=19030142"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}