diff --git a/docker/conf/modsecurity/crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf b/docker/conf/modsecurity/crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf index 4a3d0b614b5cc4d98cdb167ccd4861da0559a957..d291bb891db0d1c68e49642fc32cc458f4ccf8f0 100644 --- a/docker/conf/modsecurity/crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf +++ b/docker/conf/modsecurity/crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf @@ -82,9 +82,15 @@ SecRule REQUEST_URI "@beginsWith /wp-json/wp/v2/" \ ctl:ruleRemoveTargetByID=932105;ARGS:content,\ ctl:ruleRemoveTargetByID=941100;ARGS:content" +# "PCRE limits exceeded" errors on customization urls. SecRule REQUEST_URI "@beginsWith /wp-admin/customize.php" \ "id:1012,\ pass,\ nolog,\ ctl:ruleEngine=Off" +SecRule REQUEST_URI "@beginsWith /wp-admin/widgets.php" \ + "id:1013,\ + pass,\ + nolog,\ + ctl:ruleEngine=Off"