Hacker login attempts despite Login URL in Zone lockdown

I have a wordpress installation and despite all the login URLs being listed under zone lockdown, I still regularly get people trying to log in. My Zone Lockdown is set to only allow my own IP to access it. I have all the following URLs specified -


Any idea what is going on, I though Zone Lockdown meant nobody could get to the login page.

Probably accessing your server directly, going around Cloudflare.

Thanks for the reply. I have heard of that in this forum before but having a very low skill level, Iā€™m not sure how that is done and more importantly, is there anything I can do to stop it?

If that is the case you need to make sure your server only accepts connections from Cloudflare. You best approach your system administrator about that.

