Hi @digitallion, thank-you for sending the email over to us to show the screen you are presented with for this plugin.
If you are unable to permanently prevent the issue using the “I am certain this is a false positive” checkbox on the blocking page and leaving Learning Mode just returns to blocking the actions, we have seen issues in the past with dynamic URLs but there may be some action we can take.
Is uploading a file part of the activity when updating through FPD? You can manually take action if so, as there are usually 3 possible rules involved. “Malicious File Upload“, “Malicious File Upload (PHP)“, or “Malicious File Upload (Patterns)”. These rules can be found in Wordfence > All Options > Firewall Options > Advanced Firewall Options > Rules, after expanding the list. There are layers to how uploaded files are checked, so having to turn one of these rules off to fix your issue should still ensure malicious files are caught at a different stage of the checking process.
If you’re not uploading files when Wordfence blocks FPD, I would expect these blocks and the reason for them to show in your Live Traffic feed. You could try checking this immediately after attempting another blocked request, just to see whether you’re able to click on the Live Traffic entry to expand it for me. Could you take a screenshot of the reason Wordfence is giving for the block (usually in red text) and share it here using a site like Snipboard? You can obscure any other information like your domain name or IP addresses so long as I can see the block reason being given.
Thanks,
Peter.