Apparently, there is a line of code in the plugin that attempts to use an old version of PHP. The following is quoted from my web host:
“Looking at the cause of the block, you have a plugin that is attempting to use a version of PHP that is well over 2 years deprecated and past end of life. Resolving this issue itself would prevent further blocks while allowing mod_security to remain enabled and protecting your site.”
They also included this error message which cites simplepress:
[Tue Dec 22 14:53:42.211300 2020] [:error] [pid 13926:tid 47236583118592] [client 173.238.13.189:55751] [client 173.238.13.189] ModSecurity: Access denied with code 403 (phase 1). Matched phrase “-C” at MATCHED_VAR. [file “/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf”] [line “19”] [id “220030”] [rev “9”] [msg “COMODO WAF: Vulnerability in PHP before 5.3.12 and 5.4.x before 5.4.2 (CVE-2012-1823)||hsjccforums.ca|F|2”] [severity “CRITICAL”] [tag “CWAF”] [tag “PHPGen”] [hostname “hsjccforums.ca”] [uri “/wp-content/plugins/simplepress/admin/resources/css/fonts/sp-admin.woff”] [unique_id “X@JOxje0sSrLuCF8KIj3rwABEwY”], referer: https://hsjccforums.ca/wp-content/plugins/simplepress/admin/resources/css/spa-menu.css?ver=6.6.1