Just in case, as far as running WordPress and WooCommerce which uses WP-Cron and as far as sometimes Cloudflare catches it and block/challenge the request, I’d also suggest you to whitelist the origin host/web server IP at Cloudflare → Security → WAF → Tools → IP Access Rules with the action “allow” for your Website.
Should look like on the below screenshot as an example:
Nevertheless, Cloudflare IP addresses list can be found here:
I think I saw few topics about Jetpack and you would have to look for and allow/whitelist Jetpack IPs by adding them to the Security tab → WAF → Tools → IP Access Rules.