FunnelKit
Forum Replies Created
-
Hi @jgateman Thanks for sharing another confirmation and the help.
@wfpeter Thanks for all your help. I can confirm that the issue has been resolved and this thread can be closed now. We have also released the latest Autonami version with the fix as @jgateman said.
Really appreciate the efforts mates.
Have a good week and take care.
Hi @jgateman Thanks for jumping in. Really appreciate it.
Could we use your help to fix this problem? We’d really appreciate your input.
If this sounds good to you, then could you please drop us an email at [email protected] and tell us what setup did you follow or how did you configure WordFence on your site?
Hi Peter,
Thanks for your response.
We are yet to try the learning mode and we’d surely give it a try.
>The other option, as shown in your video, is to check the “I am certain this is a false-positive” checkbox and click the “Allowlist this action” button shown on the Wordfence blocking page. Does this cause a permanent fix or does it get flagged again next time?
We already tried this option but nothing really happens. We have to manually go to “WordFence > Tools > allow the request” to mark the call in Allowlist. Furthermore, it only unblocks the call for that particular template. If we create a new one, a new call is fired which also gets blocked. So this does not offer a permanent fix. That’s where we tried to add the
autonami-admin
endpoint to the allowlist. Unfortunately, it did not do the trick. Also, we cannot keep allowing every call, hence looking for some solution.>Aside from the above, are the web servers for customers experiencing this issue running PHP8?
We are also able to replicate the same blocking issue on PHP 7.4.3. So doesn’t seem to be a PHP8-specific issue. The video that we send has the abovementioned PHP version.
>You can discover which rule by checking the Live Traffic page after experiencing a block such as the one in your video. Expanding the entry should give a message like “blocked by firewall for XSS: Cross Site Scripting in query string…“. Let me know which one you see and we can determine whether it’s safe to turn off the rule temporarily for users seeing the problem.
I believe I’ve already shared the blocked call details in this screenshot, https://imgur.com/1B6ALwD
Were you referring to anything else?