We have a corporate WP web site that is managed by a handful of users within our organization. Were using WP v6.7.1 and WordFence v1.1.15 and approximately 2 months ago started getting our corporate Internet facing IP address blocked from access to our site hosted at Ionos.com.
We found that the workflow of 2 editing users is causing the block and although the block is easily corrected, the issue frequency has many helpdesk tickets coming in as our website is the browser home page for many users.
What we discovered is that the 2 users are using FireFox to access the WP site and update and publish content from that browser session, while on the same desktop almost simultaneously using a Chrome browser they’re refreshing and reviewing the content changes. These actions are throwing a security alert to WordFence and consequently blocking our IP address.
WordFence throws the exact error “POST received with blank user-agent and referer”. A review of this error in this forum indicates this issue can be caused by malware file reminance left behind previous site attacks deep in the folder tree of the site making cleanup difficult unless using malware specific pluggins to clean the site up. Apparently when a user edits content from a folder in the tree where the affected malware files still reside it throws the identical error to WordFence, thus blocking the IP.
We’re reluctant to whitelist our IP address as it could be an issue if local credentials were compromised.
We’re looking for additional information before we take any additional actions and because this forum had the most relevant information on this error we decided to post our topic here.