Skip to content

Conflict with Cloudflare Web Application Firewall #4805

@swissspidy

Description

@swissspidy

If you are coming from the support forums or encounter the following issue, please read carefully.

This is a tracking ticket for the work on ensuring Web Stories for WordPress does not cause issues with the Cloudflare Web Aplication Firewall (WAF) or similar solutions.

Rules that so far have been identified as possibly causing conflicts:

  • Cloudflare Specials > 100173 XSS, HTML Injection - Script Tag
  • OWASP mod_security ruleset 981176

A similar conflict exists with Sucuri's WAF.

Who's affected?

The Cloudflare WAF is available to Pro, Business, and Enterprise plans.

How do I know I am affected?

You are likely affected when using Cloudflare's WAF offering and you are unable to save or publish stories using Web Stories for WordPress.

Workaround

Cloudflare:

Add a custom Firewall rule to disable the WAF for any Web Stories-related REST API requests, like so:

Screen Shot 2020-10-02 at 12 34 56 PM

Sucuri:

Add wp-json/web-stories to the allowlist in the "Whitelist URL Paths" section.

What is being done to fix this?

We are still investigating this issue and will update this thread with any new findings.

How can I follow progress on this issue?

Subscribe to this issue using the "Subscribe" button in the sidebar:

Screenshot 2020-09-25 at 11 06 42


User reports so far

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1High priority, must do soonType: BugSomething isn't workingType: SupportQuestions & Feedback from support escalation.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions