• Random admin session logouts — confirmed caused by Wordfence, cause not yet iden

    Hi,

    We’re experiencing random, unpredictable logouts from wp-admin on our site (webhostmg.com) — no consistent pattern, happens during normal navigation with no specific trigger identified.

    What we’ve confirmed through testing:

    • Disabling the Wordfence plugin entirely stops the logouts completely — tested this twice, reproducible both times
    • Re-enabling Wordfence brings the logouts back
    • Our site sits behind Cloudflare
    • We tried changing Wordfence → All Options → “How does Wordfence get IPs” from the default auto-detection to the Cloudflare-specific option (“Use the Cloudflare CF-Connecting-IP HTTP header”) — this did not resolve the issue

    Additional context that may be relevant:

    • We also run a WordPress staging environment at a subdirectory on the same domain (/staging/) — a full clone of the site’s database (different table prefix) and files, with its own separate siteurl. Wordfence is active on this staging copy too (since plugin files are cloned along with everything else). Logging into the staging site’s wp-admin exhibits a similar symptom — the login form submits, but redirects back to the same login screen with no error shown, rather than reaching the dashboard.
    • We checked Wordfence → Firewall → Blocking — no active IP blocks
    • We checked Rate Limiting — set to “Unlimited” across all categories
    • We checked Brute Force Protection settings — nothing unusual, lockout thresholds are generous (10 failures)
    • We checked Login Security / 2FA — 2FA is set to “Optional” for our role, not enforced
    • We checked Live Traffic around the time of logouts — nothing shows as blocked; all our own traffic shows as “Human,” none flagged

    What we’re hoping to find out:
    Given disabling Wordfence entirely resolves it, there’s clearly something in Wordfence’s session/cookie handling causing this — we just haven’t been able to isolate the specific setting through the checks above. Could you help us identify what mechanism might cause this, especially given the Cloudflare + staging-subdirectory setup?

    Happy to provide diagnostic exports, server details, or anything else needed.

    The page I need help with: [log in to see the link]

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Support wfphil

    (@wfphil)

    Hi @webhostmg

    Our plugin cannot be the cause of this as it does not modify WordPress login session cookies at all in any way whatsoever so something else is the cause.

    Thread Starter webhostmg

    (@webhostmg)

    Hi @wfphil, thanks for taking a look!

    Totally get that Wordfence isn’t touching session cookies directly — that makes sense. What’s got us a bit stuck though is that we’ve tested this really carefully on our end, twice each way, and the pattern keeps repeating:

    • Wordfence off → the logouts stop completely, both times we tried
    • Wordfence back on → they come back, both times

    Since it’s so consistent, we figured it’s worth flagging in case there’s something indirect going on — maybe something at the request level rather than the cookie itself? We wondered if it could be related to a background request getting delayed or blocked (like a heartbeat or admin-ajax call), especially since we’re behind Cloudflare and also run a staging copy of the site in a subdirectory (/staging/) that shows the exact same symptom on its own login.

    No worries if it turns out to be something outside Wordfence entirely — we just wanted to share what we’re seeing in case it’s useful or rings a bell for you. Happy to send over a diagnostic export, server details, or hop on a screen-share if that’d help track it down. Really appreciate you looking into this for us!

    Thanks so much,

Viewing 2 replies - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.