diff --git a/plugins/wordpress-rule-exclusions-before.conf b/plugins/wordpress-rule-exclusions-before.conf index 89aed41..b718173 100644 --- a/plugins/wordpress-rule-exclusions-before.conf +++ b/plugins/wordpress-rule-exclusions-before.conf @@ -210,7 +210,8 @@ SecRule REQUEST_FILENAME "@endsWith /index.php" \ "t:none,\ ctl:ruleRemoveTargetById=942100;ARGS" -# Cannot update page|post in WordPress due to `x-http-method-override` header +# Cannot update page|post in WordPress due to `x-http-method-override` header. +# This rule is a copy of rule 900250 and must be synchronised with that rule. SecRule REQUEST_FILENAME "@rx /wp-json/wp/v[0-9]+/(?:posts|pages|users)" \ "id:9507146,\ phase:1,\