Membership Plugin

WordPress Membership Plugin

  • Home
  • Documentation
  • Addons
  • Support
    • Quick Setup
    • Documentation
    • Premium Addon Support
    • Paid Support
    • Support Forum
    • Support Forum Search
    • Forum Login
    • Forum Registration
  • Contact
You are here: Home

toddehb

  • Profile
  • Topics Started
  • Replies Created
  • Engagements
  • Favorites

Forum Replies Created

Viewing 9 posts - 1 through 9 (of 9 total)
  • Author
    Posts
  • December 19, 2022 at 10:01 pm in reply to: Editing sites created by Membership Plugin throws out JSON error #24936
    toddehb
    Participant

    This is from the logs. Maybe somebody here will understand how to interpret this:

    [Mon Dec 19 19:20:50.871830 2022] [:error] [pid 198258] [client XXX:52849] [client XXX] ModSecurity: Warning. Pattern match “\\\\b(?:if(?:/i)?(?: not)?(?: exist\\\\b| defined\\\\b| errorlevel\\\\b| cmdextversion\\\\b|(?: |\\\\().*(?:\\\\bgeq\\\\b|\\\\bequ\\\\b|\\\\bneq\\\\b|\\\\bleq\\\\b|\\\\bgtr\\\\b|\\\\blss\\\\b|==))|for(?:/[dflr].*)? %+[^ ]+ in\\\\(.*\\\\)\\\\s?do)” at ARGS:content. [file “/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf”] [line “412”] [id “932140”] [msg “Remote Command Execution: Windows FOR/IF Command Found”] [data “Matched Data: if you end up changing the url of this page then make sure to update the url value in the settings menu of the plugin.</p> <p style=border-top:1px solid #ccc padding-top:10px margin-top:10px ></p> free membership you get unlimited access to free membership content price: free! link the following image to go to the registration page if you want your visitors to be able to create a free membership account <img title=join now src=https://www.XXX.ne…”] [severity “CRITICAL”] [ver “OWASP_CRS/3.3.2”] [tag “application-multi”] [tag “lang [hostname “www.XXX.net”] [uri “/index.php”] [unique_id “Y6Crgs5o4VMPWxNSlINc-gAAAAQ”], referer: https://www.XXX.net/wp-admin/post.php?post=258&action=edit
    [Mon Dec 19 19:20:50.872782 2022] [:error] [pid 198258] [client XXX:52849] [client XXX] ModSecurity: Warning. detected XSS using libinjection. [file “/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf”] [line “55”] [id “941100”] [msg “XSS Attack Detected via libinjection”] [data “Matched Data: XSS data found within ARGS:content: <p style=\\x22color:red;font-weight:bold;\\x22>This page and the content has been automatically generated for you to give you a basic idea of how a \\x22Join Us\\x22 page should look like. You can customize this page however you like it by editing this page from your WordPress page editor.</p>\\x0a<p style=\\x22font-weight:bold;\\x22>If you end up changing the URL of this page then make sure to update the URL value in the settings menu of the plugin.</p>\\x0a<p s…”] [severity “CRITICAL”] [ver “OWASP_CRS/3.3.2”] [tag “application-multi”] [tag “language-multi”] [tag “platform-multi”] [tag “attack-xss”] [tag “paranoia-level/1”] [tag “OWASP_CRS”] [tag “capec/1000/152/242”] [hostname “www.XXX.net”] [uri “/index.php”] [unique_id “Y6Crgs5o4VMPWxNSlINc-gAAAAQ”], referer: https://www.XXX.net/wp-admin/post.php?post=258&action=edit
    [Mon Dec 19 19:21:48.055447 2022] [:error] [pid 198263] [client XXX:52876] [client XXX] ModSecurity: Warning. Pattern match “(?i:(?:;\\\\s*?(?:(?:(?:trunc|cre|upd)at|renam)e|(?:inser|selec)t|de(?:lete|sc)|alter|load)\\\\b\\\\s*?[\\\\[(]?\\\\w{2,}|create\\\\s+function\\\\s+.+\\\\s+returns))” at ARGS:content. [file “/usr/share/modsecurity-crs/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf”] [line “404”] [id “942350”] [msg “Detects MySQL UDF injection and other data/structure manipulation attempts”] [data “Matched Data: ; Insert Payment found within ARGS:content: <p style=\\x22color:red;font-weight:bold;\\x22>This page and the content has been automatically generated for you to give you a basic idea of how a \\x22Join Us\\x22 page should look like. You can customize this page however you like it by editing this page from your WordPress page editor.</p>\\x0a<p style=\\x22font-weight:bold;\\x22>If you end up changing the URL of this page then make sure to update the URL value in the settings menu of the plugin.</p>…”] [severity “CRITICAL”] [ver “OWASP_CRS/3.3.2”] [tag “application-multi”] [tag “language-multi”] [tag “platform-multi” [hostname “www.XXX.net”] [uri “/index.php”] [unique_id “Y6CrvLpw7DeoGiaPDNHu3wAAAAg”], referer: https://www.XXX.net/wp-admin/post.php?post=258&action=edit
    [Mon Dec 19 19:21:48.055876 2022] [:error] [pid 198263] [client XXX:52876] [client XXX] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file “/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf”] [line “93”] [id “949110”] [msg “Inbound Anomaly Score Exceeded (Total Score: 20)”] [severity “CRITICAL”] [ver “OWASP_CRS/3.3.2”] [tag “application-multi”] [tag “language-multi”] [tag “platform-multi”] [tag “attack-generic”] [hostname “www.XXX.net”] [uri “/index.php”] [unique_id “Y6CrvLpw7DeoGiaPDNHu3wAAAAg”], referer: https://www.XXX.net/wp-admin/post.php?post=258&action=edit
    [Mon Dec 19 19:21:48.056072 2022] [:error] [pid 198263] [client XXX:52876] [client XXX] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file “/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf”] [line “91”] [id “980130”] [msg “Inbound Anomaly Score Exceeded (Total Inbound Score: 20 – SQLI=5,XSS=10,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 20, 0, 0, 0”] [ver “OWASP_CRS/3.3.2”] [tag “event-correlation”] [hostname “www.XXX.net”] [uri “/index.php”] [unique_id “Y6CrvLpw7DeoGiaPDNHu3wAAAAg”], referer: https://www.XXX.net/wp-admin/post.php?post=258&action=edit

    December 19, 2022 at 6:12 pm in reply to: Editing sites created by Membership Plugin throws out JSON error #24935
    toddehb
    Participant

    Found the solution. Had modsecurity2 enabled in Apache. Disabling it removes the error with editing pages. Now I just have to find out, how to finetune this mod so it won’t interfere with this plugin anymore. Thanks for trying to help me with this matter.

    December 16, 2022 at 9:56 am in reply to: Editing sites created by Membership Plugin throws out JSON error #24918
    toddehb
    Participant

    Yes

    December 15, 2022 at 9:41 am in reply to: Editing sites created by Membership Plugin throws out JSON error #24914
    toddehb
    Participant

    Tested with this procedure already. Did not make a difference.

    December 14, 2022 at 7:43 am in reply to: Editing sites created by Membership Plugin throws out JSON error #24907
    toddehb
    Participant

    Akismet Anti-Spam
    DSGVO All in one for WP
    Duplicator
    Limit Login Attempts Reloaded
    Popup Maker
    Print, PDF & Email by PrintFriendly
    Quiz Maker
    Shariff Wrapper
    Simple Membership Google recaptcha
    Simple WordPress Membership
    Social Login, Social Sharing by miniOrange
    Statify
    Statify Widget: Beliebte Inhalte

    December 13, 2022 at 9:42 am in reply to: Editing sites created by Membership Plugin throws out JSON error #24902
    toddehb
    Participant

    Did a fresh install, but problem persists.

    December 13, 2022 at 8:12 am in reply to: Editing sites created by Membership Plugin throws out JSON error #24900
    toddehb
    Participant

    You are right. I meant Pages, like the “Join US” default page. Just translated it wrong from german. Will install a fresh copy later on.

    December 12, 2022 at 10:14 am in reply to: Editing sites created by Membership Plugin throws out JSON error #24895
    toddehb
    Participant

    Found another Bug. I enabled the feature “Enable free membership” and entered a random ID beneath. After saving ID is gone and registration page gives a message, that free membership is disabled on that site.

    December 12, 2022 at 7:48 am in reply to: Editing sites created by Membership Plugin throws out JSON error #24894
    toddehb
    Participant

    Hi,

    yes. Creating sites and editing new ones is no problem.

    Cheers, Toddehb

  • Author
    Posts
Viewing 9 posts - 1 through 9 (of 9 total)
Next Page »

Please read this message before using our plugin.

Search

Featured Addons and Extensions

  • Membership Form Builder Addon
  • Member Directory Listing Addon
  • WooCommerce Payment Integration
  • Member Data Exporter Addon

Documentation

  • Documentation Index Page

Copyright © 2026 | Simple Membership Plugin | Privacy Policy