It has nothing to do with WordPress. Your server is configured to refuse access from other domains. All you need to enable CORS Origin.
This will allow request from other domains. But it will decrease security. You might want to change the *
(allow all) to your sub domain. Just put it in your .htaccess
file.
<IfModule mod_headers.c>
<FilesMatch "\.(jpg|png|gif)$">
Header set Access-Control-Allow-Origin "*"
</FilesMatch>
</IfModule>
Related Posts:
- How to redirect all HTTP requests to HTTPS
- Best way to eliminate xmlrpc.php?
- HTTP Security Headers in wp-config
- Downloading File from Outside Web Root
- Dangers to allowing Access-Control-Allow-Origin: * for Feeds only?
- Any any insecure http:// URLs left in wordpress?
- Specific Page/Post Need to Stay Non SSL
- https images not displaying
- What is the difference between a cer, pvk, and pfx file?
- How to solve “Kernel panic – not syncing – Attempted to kill init” — without erasing any user data
- Error `sec_error_revoked_certificate` when viewed in Firefox only
- Convert .pfx to .cer
- Why should I use the esc_url?
- How to remove rest api link: in http headers?
- Why escape if the_content isnt?
- Full path disclosure on rss-functions.php
- What to use instead of wp_kses() in user output
- Are the default salts secure?
- is_email() VS sanitize_email()
- Subscribe to email for security fixes?
- How to escape custom css?
- Understanding SVG vulnerabilities in WordPress related to a specific fix
- Moving wp-config.php: Can this be done after site launch?
- How to secure or disable the RSS feeds?
- Does WordPress contain “default” anti-SQL injection code that responds with a 404 error?
- Make password invalid once logged out of password-protected page
- How to get WordPress to save upload file beyond web root [closed]
- Is security a problem in WordPress?
- Moving wordpress out of the public directory
- Logout via Subdomain, non-wordpress page on a different server?
- wp_remote_get() not retrieving pages properly
- If Modified Since HTTP Header
- How can I tell who changed the password?
- Why am I sometimes getting a 404 error when I try to update a page with Elementor?
- WordPress website Security [closed]
- Do I need to use the esc_html() function on hard coded links?
- Can’t reset WordPress password
- Is the “lost password” feature truly a vulnerability?
- Disabling the X-Redirect-By response header
- Frontend Password change
- Is it possible to reduce the minimum character length for passwords?
- Handling email piping attachments and detecting unsupported file types
- Why Better WP security plugin returns 418 I’m a Teapot “error”?
- site get login attempts after htaccess ip restriction
- Is it good security advice to install wordpress in subdirectory but link to root?
- Why was my blog post inserted lot’s of ad links by others?
- Moving wp-config.php up 2 levels
- How Could I sanitize the receive data from this code
- WordPress SQL Injections through User Agent
- Should I Worry About SQL Injection When Using wp_insert_post?
- Is there a way for a user to have an alias?
- Security threat with `home_url`?
- When is wp_set_password() called or how to capture a password
- How to protect wp-admin through .htaccess?
- Something is unescaping all html entities before output to browser [closed]
- Headers Content-Security-Policy CSP Major Issue
- Frequently getting attacks on admin-ajax.php, wp-cron.php, xmlrpc.php and wp-login.php
- How to get WordPress to send Password Reset Link Email instead of New Password?
- WordPress 502 | Header Upstream send too big
- Verifying that I have fully removed a WordPress hack?
- Large Session Tokens
- How to change permissions of WordPress and/or apache on macOS securely?
- Using an Encryption class in a WordPress Plugin
- Limit Login Attempts BEFORE PHP is executed?
- Safe to say WordPress security releases don’t have database upgrades
- Config file with no Keys..?
- How much should I worry about these messages?
- Security concerns with external links
- Uploading .webm format on WordPress results in security guidline breach and fail
- fail2ban to prevent Brute Force Attacks on WordPress?
- .htaccess password protection bypassed
- Session Cookie security questions
- How to give the same error message when the wrong password or wrong username is used?
- Storing FTP details in wp-config.php
- Spam injected in w3 total cache page cache [closed]
- Adding Security Keys?
- How might I sanitize an XML file before WP Import? (Does wordpress verify or clean text when importing from an XML document? )
- Secret keys in SCM
- Secure Server after configuration
- Uploading attachment (pdf) and prevent download for anonymous user
- After limiting the access to my wp-login.php by IP through .htaccess, all my password-protected posts stopped working. What’s the best solution now?
- Block JSON access over the net
- Can someone do something to my website if I posted a snapped image of the header and covered my logo? (On reddit, when explaining a question)
- Scan multiple websites for malware that are in same webhost root?
- The in-famous Unable to locate WordPress Content directory (wp-content) and the Direct Method
- Security: AWS (shared hosting) claims template file malicious
- Enable CORS for getting an inline SVG by URL
- Modify wp headers on specific page
- How to check whether a site has been compromised without browsing into it?
- My site thinks it’s secure when it is fact not
- Is it possible to only have the admin interface bind to the local loopback?
- PHP Code Sniffer – WordPress VIP Coding Standards
- Trying to understand nature of hacking
- Default installation permissions for wp-config.php
- Correct setup to block file modifications from hackers
- checking the form submit in right order
- Our security auditor is an idiot. How do I give him the information he wants?
- I am under DDoS. What can I do?
- SSH keypair generation: RSA or DSA?
- WordPress – tracking options