diff --git a/docker/conf/modsecurity/crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf b/docker/conf/modsecurity/crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf index 93c06a7f662827d1c33d94fccc27a3d3fed26008..673aef72b3548191712ca876658207e0c1e9f1e8 100644 --- a/docker/conf/modsecurity/crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf +++ b/docker/conf/modsecurity/crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf @@ -71,3 +71,12 @@ SecRule REQUEST_URI "@beginsWith /wp-admin/network/settings.php" \ ctl:ruleRemoveTargetByTag=OWASP_CRS;ARGS:wp-piwik[tracking_code],\ ctl:ruleRemoveTargetByTag=OWASP_CRS;ARGS:wp-piwik[noscript_code]" +# Gutenberg comments are misinterpreted. +SecRule REQUEST_URI "@beginsWith /wp-json/wp/v2/template-parts" \ + "id:1011,\ + phase:2,\ + pass,\ + nolog,\ + ctl:ruleRemoveTargetByID=932105;ARGS:content,\ + ctl:ruleRemoveTargetByID=941100;ARGS:content" +