It knows to happen due to the WordPress using HTTP/1.0 and empty user-agent, therefore while executing WP-Cron or some other related JSON/REST API request via plugin which triggers the WAF rules (as it should normally).
Might be something was cached as well
Make sure the Caching Level is set as “Standard” at Cloudflare dashboard.
Regarding Browser Cache TTL, try setting it to “Respect Existing Headers”.
Therefore, use the button which says “Purge Everything” to clear the cache at Cloudflare.
Also, try opening your Website in a different Web browser, or delete cache from your current one to see if there’s any difference at all.
If not, try to disable Rocket Loader to see if anything different:
I’ve found DIVI loads better with higher or more generous PHP settings.
What’s your DIVI Site Report telling you about your web server PHP values?