• Resolved Mary Notari

    (@marynotari)


    WordPress 6.1.1 running Twenty Twenty Three theme. No plugins. PHP 7.4 Fast CGI.

    When editing in the site editor, I was trying to change the style from Default to Sherbet but was constantly getting “Saving failed” error messages. I got the same error when trying to save any of the other styles too.

    I went to my host to check my error log and found multiple error messages that seemed to indicate that DreamHost’s firewall was reading any global changes to the theme style in WordPress as a potential attack. Here is one of the error messages in part:

    ModSecurity: Access denied with code 418 (phase 2). Operator GE matched 7 at TX:anomaly_score. [file "/dh/apache2/template/etc/mod_sec3_CRS/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 105)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.marynotari.com"] [uri "/wp-json/wp/v2/global-styles/1039"] [unique_id "Y@w7osDNq2Y@UP15HZRN9gAAAAE"], referer: https://www.marynotari.com/wp-admin/site-editor.php?postType=page&postId=431

    After some googling I found that disabling the firewall on the Dreamhost side solved the problem.

    I’ve since contacted DreamHost with the issue. I’m deeply uncomfortable with not having that extra layer of security. Is there something that can be done about it on the WordPress side?

    The page I need help with: [log in to see the link]

Viewing 1 replies (of 1 total)
  • Hi @marynotari, this issue is indeed coming from a conflict with Dreamhost’s server configuration, as discussed here.

    I’m deeply uncomfortable with not having that extra layer of security. Is there something that can be done about it on the WordPress side?

    I believe this problem is coming from a misconfiguration with the way Dreamhosts’s firewall is set up, not so much with WordPress lacking security in and of itself. If your plugins are up to date and you are using strong & unique passwords, that should be more than enough.

    I hope that helps!

Viewing 1 replies (of 1 total)
  • The topic ‘“Saving failed” in Site Editor’ is closed to new replies.