I have 3 sites on the free Cloudflare plan. I have the same security rules on all 3 pages. The one rule is to apply the ReCaptcha if the URL contains wp-login.php or wp-admin.
Everything’s been working great for about a month, until one of the sites started going into an infinite loop as soon as I go to the /wp-admin/ part of the site. Nothing changed, and I’ve checked the other 2 sites do not have the loop bug. I’ve triple-checked the rules, they are EXACTLY the same across all 3 sites.
I’ve also cleared the cache on the site, browser, and Cloudflare, but the problem remains. Tried different browsers and also changing my IP on VPN but no go.
I have a rule that only allows my country to log in. As you are outside you would hit the 1020 after the capture.
I have add blockers but it’s turned off for my own sites. Incognito is also stuck in an infinite loop. When I add my own IP and ISP ASN with an allow rule, it works. So I guess Cloudflare somehow flagged my IP as a bot or attack. But nothing in the logs anywhere, and no idea why it works on the other two sites with exact same settings. It’s very frustrating…
I don’t hit the 1020 after the captcha challenge, as my country is allowed to log in. However, I don’t get past the captcha either. Tried connecting on the wife’s laptop from a different network, and I can get through after the captcha challenge. So, somehow Cloudflare has flagged me as a threat or bot I guess… no idea how that works… Cannot allow my IP, as it is changed every 2 hours by my ISP…
Update: So after a 24 hour period the infinite loop is resolved. I can log in again. Did not change anything to cause it, and did not do anything to resolve it either. Stumped as to why it was caused in the first place, and a bit frustrating that it happened with finding the root cause so that it can be resolved permanently.
I am sorry, I cannot even test it as I just tried to figure out if the ReCaptcha is on the login form as a part of Google ReCaptcha (WordPress plugin), or a “Captcha” from Cloudflare?, as far as I get “Access denied” due to Firewall rules.
One rule, okay.
Is this the first rule?
Are there more rules with the “block” or “challenge” action?
Does it mean that each request under /wp-admin/ is being challenged by the captcha, or just the ones that goes to the /wp-admin/ (not being logged in) and it redirects to wp-login.php?
Even a basic visitor to your Website, if your theme uses /wp-admin/admin-ajax.php for some requests like posts loading, cart or checkout page, WooCommerce, Jetpack, etc?
Meaning, each visitor is being challenged?
Could that be the reason why you are in a loop, if so? (not sure if it works when user oncely passes the captcha, is it being challenged again if it goes to dashboard, edit posts … where are hundreds of the requests made to /wp-admin/ for CSS, JS, Ajax, etc.)
If you are using Cloudflare Captcha, may I ask what do you get in Firewall events for the users trying to access /wp-admin/ from your allowed country?
Cause: https://agsbetesdacradock.co.za/wp-content/uploads/2021/05/AFM.png is going to https://agsbetesdacradock.co.za/twk-wp-content/uploads/2021/05/AFM.png is redirecting to https://agsbetesdacradock.co.za/twk-wp-content/uploads/2021/05/AFM.webp
Some HTTP headers for wp-login.php or /wp-admin/ like wp-cf-super-cache is indicating you are using WP Cloudflare Super Page Cache plugin, which is not an official Cloudflare plguin: