403 Forbidden Loopback/REST API Error with Bluehost-managed Cloudflare CDN
-
Hello Wordfence Support,
I am experiencing a 403 Forbidden error in the Wordfence Diagnostics page for the loopback/REST API test.
Environment:
- WordPress: Latest version
- Wordfence: Latest version
- Hosting Provider: Bluehost (Pro 150 Hosting)
- CDN: Bluehost-managed Free Cloudflare CDN (I do not have a separate Cloudflare account.)
Issue:
When the Bluehost-managed Cloudflare CDN is enabled, Wordfence Diagnostics reports:“wp_remote_post() test back to this server failed! Response was: 403 Forbidden”
Bluehost has thoroughly investigated the issue and confirmed the following:
- No server-side ModSecurity rules are blocking the requests.
- No firewall or hosting configuration issues were found.
- The issue is specific to my website and is not affecting all Bluehost websites using the Bluehost-managed Cloudflare CDN.
- They believe the issue may be related to the interaction between Wordfence and Cloudflare, but they cannot identify which requests are being blocked because Wordfence is a third-party plugin.
I need to keep both Wordfence and the Bluehost-managed Cloudflare CDN enabled. Disabling Cloudflare is not an acceptable solution.
Could you please help me identify:
- Which Wordfence request is receiving the 403 response?
- Is this a known compatibility issue with Bluehost-managed Cloudflare?
- Are there any Wordfence settings or configuration changes that will allow both Cloudflare and Wordfence to work together without disabling Cloudflare?
Thank you.
You must be logged in to reply to this topic.