Recent Posts

Pages: 1 2 [3] 4 5 ... 10
21
Information / Re: New WordPress vulnerability - CVE-2026-87902
« Last post by Starburst on September 23, 2026, 04:29:28 PM »
Thank You
22
I have a CWP Pro virtual server running AlmaLinux 8.10 and CWP 1.14

The server is never under any appreciable load - max 33% of processor capacity and 4GB of RAM from 16GB total. Checking the Apache Server Status via the CWP control panel, everything looks sane - 12 spawned servers, utilises 1.5GB RAM, 272 tasks.

All sites on the server use PHP-FPM, some stuck on legacy PHP7.4 but most running PHP8.3

Cloudflare returns a timeout error of 522 on some sites, seemingly at random but rather often. If I disable Cloudflare, I get the same timeouts but with a vanilla error message in the browser. So Cloudflare is not at fault here.

I have tried various tactics to prevent this:

a) Apache was reporting it had run out of RequestWorker processes, so I included the following snippet via conf/extra/httpd-mpm.conf (Apache runs with the MPM Evnt mod on my server).

Code: [Select]
<IfModule mpm_event_module>
    StartServers            25
    ServerLimit             32
    MinSpareThreads         75
    MaxSpareThreads        250
    ThreadsPerChild         25
    MaxRequestWorkers    800
    MaxConnectionsPerChild   0
</IfModule>

b) When that didn't solve the problem, I also increased the number of max PHP-FPM processes in the default template and for individual sites. I increased from the default of MaxChildProcceses 4 to 25.

c) I enabled KeepAlive which I don't think is enabled by default, via self-authored snippet included in conf/extra/httpd-keepalive.conf

Code: [Select]
KeepAlive On
MaxKeepAliveRequests 100
KeepAliveTimeout 5

None of the above has resolved the problem. I am at a loss. Furthermore, some of the sites show extremely poor performance. Yet the server has loads of spare capacity.

Anyone got any insight here?

I have checked if disabling the firewall made any difference (in case it was blocking Cloudflare IP addresses). It did not and it is not.
23
Updates / Re: Unable to load dynamic library 'intl'
« Last post by venty on September 23, 2026, 05:29:19 AM »
What do you get when you execute the following command on your server/vps ?

Code: [Select]
cat /etc/redhat-release
and

Code: [Select]
/usr/local/cwp/php71/bin/php --version


Hi,

For `cat /etc/redhat-release`, I get the following:

AlmaLinux release 9.8 (Olive Jaguar)

For `For `cat /etc/redhat-release`, I get the following:

https://prnt.sc/9zVq-w9js5Y9

When I start executing the code from the article:

https://starburst.help/control-web-panel-cwp/control-web-panel-cwp-admin-tutorials/fix-for-php-startup-unable-to-load-dynamic-library-intl-cwp-error-on-almalinux-9


for `rpm -q libicu`, I get: libicu-67.1-10.el9_6.x86_64

...but the error persists... what should I do?


BR
Venty



24
Information / New WordPress vulnerability - CVE-2026-87902
« Last post by 6Sense on September 23, 2026, 01:53:32 AM »
Here's what my data centre emailed me. I only host a handful of WP sites but have updated.

We are writing to advise you of a critical security vulnerability that has been disclosed in WordPress Core and addressed in the latest security release. CVE-2026-87902 – An unauthenticated path traversal issue in page-template resolution leading to conditional remote code execution.

Due to the severity of this vulnerability, we strongly recommend updating your WordPress installation immediately.

These WP versions are reported as safe:
WordPress 7.1.2
WordPress 7.0.6
WordPress 6.9.9
WordPress 6.8.10
WordPress 6.7.9
WordPress 6.6.9
WordPress 6.5.12
WordPress 6.4.12
WordPress 6.3.12
WordPress 6.2.13
WordPress 6.1.14
WordPress 6.0.16
WordPress 5.9.18
WordPress 5.8.17
WordPress 5.7.19
WordPress 5.6.21
WordPress 5.5.22
WordPress 5.4.23
WordPress 5.3.25
WordPress 5.2.28
WordPress 5.1.26
WordPress 5.0.29
WordPress 4.9.33
WordPress 4.8.32
WordPress 4.7.37

I also added some new custom ModSec rules and have shared them below

Code: [Select]
# --------------------------------------------------------------------
# Virtual patch for unauthenticated traversal attempts
# --------------------------------------------------------------------

SecRule REQUEST_URI "@rx (?i)(?:%2e%2e|%252e%252e)" \
    "id:10024,\
    phase:1,\
    t:none,\
    deny,\
    status:403,\
    log,\
    msg:'CVE-2026-87902 - WordPress encoded path traversal attempt',\
    tag:'CVE-2026-87902',\
    tag:'WordPress',\
    tag:'path-traversal',\
    severity:CRITICAL"

# --------------------------------------------------------------------
# CVE-2026-87902 - encoded traversal in request parameters
# --------------------------------------------------------------------

SecRule ARGS "@rx (?i)(?:\.\./|%2e%2e(?:/|%2f)|%252e%252e(?:/|%252f))" \
    "id:10025,\
    phase:2,\
    t:none,\
    deny,\
    status:403,\
    log,\
    msg:'CVE-2026-87902 - WordPress path traversal attempt',\
    tag:'CVE-2026-87902',\
    tag:'WordPress',\
    tag:'path-traversal',\
    severity:CRITICAL"

25
Updates / Re: Unable to load dynamic library 'intl'
« Last post by Starburst on September 22, 2026, 10:36:24 PM »
https://starburst.help/control-web-panel-cwp/control-web-panel-cwp-admin-tutorials/fix-for-php-startup-unable-to-load-dynamic-library-intl-cwp-error-on-almalinux-9/

Hi,

I plan to follow the steps in article, but I didn't understand the explanations following the line:

"Thanks to @cyberspcae over at the CWP forums for the below"
(Has been modified if your server shows PHP 7.4.33 on AlmaLinux 9.8)

What should I execute—which lines should I run and which ones shouldn't I?

Thanks...

BR
Venty

I had answered you on that, that it was a thanks to Cyberspace, and isn't in any command areas on the KB.

Code areas look totally different than comment areas.

Code areas, are grey background with black text.

The article is at:
https://starburst.help/control-web-panel-cwp/control-web-panel-cwp-admin-tutorials/fix-for-php-startup-unable-to-load-dynamic-library-intl-cwp-error-on-almalinux-9

Here is a snippet of the area, I don't know how to blonde proof any further, except to delete.

https://i.postimg.cc/J0ZtP8kQ/Screenshot-2026-09-22-223151.png
26
Updates / Re: Unable to load dynamic library 'intl'
« Last post by cyberspace on September 22, 2026, 09:18:59 PM »
What do you get when you execute the following command on your server/vps ?

Code: [Select]
cat /etc/redhat-release
and

Code: [Select]
/usr/local/cwp/php71/bin/php --version
27
Updates / Re: Unable to load dynamic library 'intl'
« Last post by venty on September 22, 2026, 05:36:43 PM »
https://starburst.help/control-web-panel-cwp/control-web-panel-cwp-admin-tutorials/fix-for-php-startup-unable-to-load-dynamic-library-intl-cwp-error-on-almalinux-9/

Hi,

I plan to follow the steps in article, but I didn't understand the explanations following the line:

"Thanks to @cyberspcae over at the CWP forums for the below"
(Has been modified if your server shows PHP 7.4.33 on AlmaLinux 9.8)

What should I execute—which lines should I run and which ones shouldn't I?

Thanks...

BR
Venty
28
I would verify the effective ModSecurity configuration rather than relying on what the CWP UI reports.

First confirm which ruleset Apache is actually loading, whether the active include points to the .conf file rather than .conf.example, and whether ModSecurity is running in blocking mode rather than detection-only mode. Then send a harmless request that should trigger a known CRS rule and confirm the event appears in the ModSecurity audit log.

That separates three different problems: the rules aren't being loaded, they're loaded but only detecting, or CWP is changing the configuration during an update/rebuild.

I'd also record the file timestamps before and after a CWP update/rebuild. If the working configuration is being replaced automatically, that gives you a much clearer point to investigate than repeatedly renaming the file.

I develop CWP7 Resource Shield, which is designed around this broader problem of coordinating CWP traffic protection instead of relying on a single defensive layer. It can combine traffic-pattern analysis with Cloudflare and optional CSF workflows. I'm mentioning it because this is directly related to the problem it was built for; I'd still verify the active ModSecurity configuration first before adding another layer.
29
Thanks for posting this, especially the note that your own server was already attacked.

If exploitation actually reached the server, I wouldn't stop at upgrading CSF or setting MESSENGERV3 = 0. Those close the known entry point, but they don't establish whether anything was left behind.

I would also check recent systemd service creation/modification, unexpected cron entries, new or modified SSH authorized_keys, unusual listening ports/processes, recent executables in /tmp and similar writable locations, and suspicious processes that return after being killed.

Comparing timestamps around the suspected attack window can be particularly useful. If something was executed as the Apache user, I'd also inspect files/directories writable by that context and correlate them with the web/access logs.

I develop the CWP7 Security Audit Module, which automates a number of these evidence checks specifically for CWP7 servers and reports them as PASS / INFO / REVIEW / FAIL. I built it largely because checking these persistence indicators manually after CWP incidents became repetitive. If useful, I can explain the checks it performs — but regardless of the tool, I would definitely do a post-compromise review after applying the CSF fix.
30
Backup / Re: Backup Manager Beta is not remembering password in destination
« Last post by adrianofnatal on September 21, 2026, 09:09:00 PM »
Never worked after some update around 0.9.xxx.

I use S3.
Manually works, upload to S3.
Scheduled does not work.
Pages: 1 2 [3] 4 5 ... 10