[ad_1]
I found an article dated Nov 2021 on wpsec that suggested turning on a setting :
**setvar:tx.crs\_exclusions\_wordpress**
My question is do the 903 EXCLUSIONS RULES files also need to be present ? or does this work currently natively within modsec’s programming (perhaps this setvar replaces those rule sets?)
(modsec2 and OWASP3; for some reason I have no REQUEST-903 rule sets on the server)
[ad_2]