• Debian 11 has reached its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.81 is the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Nginx filter false positve

Poggenpower

New Pleskian
Following Security Measures are not restricted to the word press base path like others, which cause false positives if other software like nextcould is installed on the same server:

Block access to sensitive files
Enable bot protection
Block access to potentially sensitive files

E.g.
location ~* "(?:wp-config\.bak|\.wp-config\.php\.swp|(?:readme|license|changelog|-config|-sample)\.(?:php|md|txt|htm|html))"
should look like:
location ~* "^/YOURWPROOT/.*(?:wp-config\.bak|\.wp-config\.php\.swp|(?:readme|license|changelog|-config|-sample)\.(?:php|md|txt|htm|html))"

There are already a lot of rules that have this condition:

Code:
        #extension wp-toolkit begin
        location ~* "^(?:/YOURWPROOT/)wp-content/uploads/.*\.php" { deny all; }
        location ~* "^(?:/YOURWPROOT/)wp-includes/(?!js/tinymce/wp\-tinymce\.php$).*\.php" {
                deny all;
        }
        location ~* "^(?:/YOURWPROOT/)wp-admin/(load-styles|load-scripts)\.php" { deny all; }
        if ($http_referer !~* "^$|^https?://(.*\.)?(schmu\.net|google\.com)(:|/|$)") {
                rewrite "^(?:/YOURWPROOT/)wp-content/uploads/.*\.(gif|png|jpeg|jpg|svg)$" "/YOURWPROOT/fake-hotlink-stub" last;
        }

In Tools like nextclould request to "readme.txt" or "changelog.md" are absolutely valid and won't mean someone is doing evil things.

WordPress Toolkit version: 4.10.2-4121

Bye
Thomas
 
Back
Top