Home Forums WoodMart support forum Theme does not allow me to save any changes on theme settings!

Theme does not allow me to save any changes on theme settings!

Viewing 6 posts - 1 through 6 (of 6 total)
  • Author
    Posts
  • #254609

    Dmaspot
    Participant

    Here is a short screen rec of this issue: https://www.screencast.com/t/jddpZEEDIVMG

    The issue still exists though, and the host is adamant that it’s not php.ini related, as the error message is caused by theme code that triggers a firewall rule for cross-site scripting attack:

    Attachments:
    You must be logged in to view attached files.
    #254619

    Hello,

    I watched the video you attached.

    403 Forbidden error says that your server blocks our theme’s request to save the settings. Please, contact your hosting provider and ask them to review this problem and fix it.

    You can check one of the previous customers have this issue and fixed it by their hosting:
    https://xtemos.com/forums/topic/403-forbidden-access-error-when-saving-theme-settings-2/

    Regards.
    Xtemos Studios.

    #254633

    Dmaspot
    Participant

    I have contacted my hosting provider and they sent me the message I sent you already, that there should be code fixes by your side.

    Please read again the message in the private content.

    Thanks

    #254656

    Hello,

    I have read the message you sent in the private content area.

    The MOD_Security is from the server side not from our theme.

    Try to disable mod_security on your server. It seems to block Theme Setting’s “save” requests. Contact your hosting provider for help.

    Best Regards.

    #254657

    Dmaspot
    Participant

    I contacted the hosting provider and they informed me that if they do whitelisting there would be security vulnerabilities as long as there will be no firewall to filter potential attacks.

    Hey insist that there should be some code fixing from your side.

    Thanks

    #254665

    Hello,

    It is not required to be disabled completely. As was proposed by your hoster, some requests can be whitelisted. You need to provide them with the requested information so they can whitelist this particular request.

    Best Regards.

Viewing 6 posts - 1 through 6 (of 6 total)