• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Question How to overrde "Security of the wp-content folder" with .htaccess

Laurence@

Regular Pleskian
What are the .htaccess directives to override this function. Say a user wants to secure /wp-content but allow 2 scripts to execute. Anyone know?
 
What are the .htaccess directives to override this function. Say a user wants to secure /wp-content but allow 2 scripts to execute. Anyone know?
I don't use .htaccess. However, you can turn off the wp-content security in the WordPress settings and re-enable it manually in your "Additional nginx directives" settings for each domain. Do something like this, enabling the PHP access for specific files then disabling it for all others:

Code:
# Allow PHP for specific files while stopping all other PHP in wp-content (this is only for https content)
location ~* "^/wp-content/.*myspecialfile.php" {
   proxy_pass   https://myserveripaddress:7081;
   proxy_set_header Host   $host;
   proxy_set_header X-Real-IP   $remote_addr;
   proxy_set_header X-Forwarded-For   $proxy_add_x_forwarded_for;
}
location ~* "^/wp-content/.*\\.php" { deny all; }
 
Back
Top