You're editing a page — often in Elementor, WPBakery or a form builder — and a save or an "insert template" fails with 400 Bad Request or 403 Forbidden, while the site itself loads fine. That's ModSecurity, the web application firewall, misreading a legitimate request as an attack.
It's a false positive and we can whitelist the specific rule for your account in a couple of minutes. Open a ticket with:
- the page you were editing and what you were doing when it failed,
- the exact time, so we can find the entry in the firewall log,
- a screenshot of the error if you have one.
Please don't work around it by turning off security plugins or moving to plain http:// — neither helps and both make things worse. Once the rule is excluded the editor works normally and stays working.