diff --git a/conf/modsecurity/crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf b/conf/modsecurity/crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf index 8213b19c9984c764062b71007bb7fbefcd4f097f..efabd1aac393ce97c262ff7f391359fbdbe3be2c 100644 --- a/conf/modsecurity/crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf +++ b/conf/modsecurity/crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf @@ -41,7 +41,11 @@ SecRule REQUEST_FILENAME "@endsWith /wp-admin/admin-ajax.php" \ ctl:ruleRemoveTargetByTag=CRS;ARGS:widget-event_list_widget[1][title],\ ctl:ruleRemoveTargetByTag=CRS;ARGS:widget-event_list_widget[1][location_length],\ ctl:ruleRemoveTargetByTag=CRS;ARGS:widget-event_list_widget[2][title],\ - ctl:ruleRemoveTargetByTag=CRS;ARGS:widget-event_list_widget[2][location_length]" + ctl:ruleRemoveTargetByTag=CRS;ARGS:widget-event_list_widget[2][location_length],\ + ctl:ruleRemoveTargetByTag=language-powershell;ARGS:widget-event_list_widget[1][title],\ + ctl:ruleRemoveTargetByTag=language-powershell;ARGS:widget-event_list_widget[1][location_length],\ + ctl:ruleRemoveTargetByTag=language-powershell;ARGS:widget-event_list_widget[2][title],\ + ctl:ruleRemoveTargetByTag=language-powershell;ARGS:widget-event_list_widget[2][location_length]" # Filter out certain args (all URIs) for the pgp email plugin. SecRule REQUEST_URI "@beginsWith /" \