We have x-frame-option and content security policy headers configured on our nginx server on our Wordpress hosted site. We also have the Cloudflare Wordpress plugin enabled with APO and Rocket loader.
Our cached page shows without the CSP or x-frame-options set to deny
Do a Purge Everything in your cache here so Cloudflare fetches a fresh copy. Something newer than the 110,000 seconds that resource has been sitting in cache.