WP automatically updated to 6.8 and now my uploads are being blocked

Viewing 8 posts - 1 through 8 (of 8 total)
#205470

Anthony Zackin
Participant

I am trying to go back to WP 6.7.2 but when will a version of DM work with 6.8 correctly? Thanks.

#205471

Tahasin
Moderator

Hello,

Thanks for reaching out. Are you experiencing any issues with WordPress 6.8 and the Download Manager plugin? Please provide a bit more detail so we can better understand the situation and assist you accordingly. As far as we’ve tested, Download Manager is working fine with version 6.8.

Regards

#205504

Anthony Zackin
Participant

I had to back out of WP 6.8 to WP 6.7.2 AND use the previous version of DM for my files not to be blocked after uploading, i.e., the load failed. I had auto-update set for both and it created a huge headache. Maybe I am the only one to have a problem but, nonetheless, it happened. To be honest, since I had to make a number of permutations of the various software to figure out the culprit(s) I am not 100% sure but I THINK that the new version of DM also had a problem with WP 6.7.2 as well. I won’t swear to it but I believe that is the case. Only when I restored the previous version of DM did the problem go away.

#205506

Graham Thompson
Participant

I was experiencing the same problem. Thought it was due to the 6.8 wordpress update. Winds up it was cloudflare WAF, OWASP Core ruleset to be exact.

If anyone knows how to keep the OWASP Core Ruleset WAF enabled and allow download manager to work I would be grateful.

#205508

Tahasin
Moderator

Hello, @Anthony

Kindly try updating the plugin to the latest version and let me know if the problem still persists.

Please check and let me know.

Regards

#205509

Tahasin
Moderator

Hello, @Graham

Please open a new ticket describing the issue, and we will do our best to resolve the problem if it’s related to Download Manager.

Regards

#205533

Graham Thompson
Participant

Hi Tahasin,

I’m not sure how Download Manager is uploading files, but it is absolutely the OWASP core WAF rules that were causing the issues we encountered. We use Cloudflare, but I would assume any WAF with the OWASP core ruleset would see the uploads as a threat and block the transfer. I don’t need assistance per se, leaving this for others that may encounter the same thing. If it can be addressed so these rules can be re-enabled, that would be great, but not a showstopper for us.

The rules that are triggered by download manager trying to upload are:

“[\”3500d96add324dcbbc0a93b2bd22c723\”,\”a882bfdf91b3440b83020de61d8cf992\”,\”753c98e3a15f4a389ea0b196c91b7247\”,\”c4926d96b87647329947ec2ccbc01671\”,\”a2e88d6e0e604f05b9e660567fbedd30\”,\”be337f9e5266487a8e67c008d732161b\”,\”f2db062052cf453fbe9e93f058ecf7e7\”,\”6afe6795ee6a48d6a1dfe59255395a78\”,\”cda7fcb45e304a589567d2021821e480\”,\”293e73c033b34a2290481c4718a93bb2\”,\”5a6f5a57cde8428ab0668ce17cdec0c8\”,\”d12ad6d1bc0c42b3affe0cee682bb405\”]

If these are marked as skip when /wp-admin/admin-ajax.php is the target, the uploads work.

#205538

Tahasin
Moderator

Hello, @Graham

Please open a new ticket and we will assist you there.

Thanks for your understanding.

Viewing 8 posts - 1 through 8 (of 8 total)

You must be logged in to reply to this topic.