Mitigating Attacks on WordPress When Running Under a Full CDN Like Cloudflare: A Guide | HackerNoon
Briefly

The most effective way to prevent bots from spamming your server is to drop them at the firewall, using tools like Denyhosts or fail2ban.
Cloudflare acts as a middleman between your server and the users, making it impossible for your firewall to see the original user's IP.
Blocking IPs that belong to Cloudflare can cause legitimate users to lose access to your site, as their requests are masked by Cloudflare's infrastructure.
To effectively manage malicious traffic while using Cloudflare, it’s essential to employ alternative filtering methods, not reliant on blocking the Cloudflare IPs.
Read at Hackernoon
[
]
[
|
]