Cobra Forum

Plesk Panel => Others => Topic started by: mahesh on Jan 29, 2025, 07:28 AM

Title: WordPress site with WooCommerce is down in Plesk: 403 Forbidden
Post by: mahesh on Jan 29, 2025, 07:28 AM
Symptoms
Forbidden
You don't have permission to access this resource.
Apache Server at example.com Port 443

404 Not found
ModSecurity: Warning. Pattern match "[\\[\\]\\x22',()\\.]{10}$|\\b(?:union\\sall\\sselect\\s(?:(?:null|\\d+),?)+|order\\sby\\s\\d{1,4}|(?:and|or)\\s\\d{4}=\\d{4}|waitfor\\sdelay\\s'\\d+:\\d+:\\d+'|(?:select|and|or)\\s(?:(?:pg_)?sleep\\(\\d+\\)|\\d+\\s?=\\s?(?:dbms_pipe\\.receive_message\\ ..." at REQUEST_COOKIES:sbjs_first. [file "/etc/httpd/conf/modsecurity.d/rules/comodo_free/22_SQL_SQLi.conf"] [line "66"] [id "218500"] [rev "18"] [msg "COMODO WAF: SQLmap attack detected||example.com|F|2"] [data "Matched Data: |||id=(none) found within REQUEST_COOKIES:sbjs_first: typ=organic|||src=google|||mdm=organic|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "example.com"]
Cause
WooCommerce +8.5 triggers the web application firewall rule 218500 from the Comodo ruleset, blocking access.

Resolution
WooCommerce is working to fix this. In the meantime, the rule can be disabled to work around the problem.