• Resolved mevelardi

    (@mevelardi)


    Hello Wordfencers,
    I have Wordfence installed with a new Woocommerce site which we’re testing. every time a customer logs out of the account it is redirected to this page https://steams3000.com/wp-login.php where the following msg appears:

    You are temporarily locked out

    You have been temporarily locked out of this system. This means that you will not be able to log in for a while.

    Return to the site home page
    If you are a WordPress user with administrative privileges on this site please enter your email in the box below and click “Send”. You will then receive an email that helps you regain access.

    Click here to learn more: Documentation

    Generated by Wordfence at Tue, 25 Sep 2018 14:48:09 GMT.
    Your computer’s time: Tue, 25 Sep 2018 14:47:57 GMT.

    I am using Avada theme. I have a few extra customizations and Woocommerce plugins but the problem presents itself as soon as the Avada core plugins, woocommerce and Wordfence are activated (all the rest are not).
    Thank you in advance for your assistance!

    The page I need help with: [log in to see the link]

Viewing 12 replies - 1 through 12 (of 12 total)
  • Hi @mevelardi!
    It sounds like the WordPress login hook is being triggered when the user is logging out. Two questions

    1. How many login attempts do have set Wordfence to allow?
    2. Do you have the option set to “Immediately lock out invalid usernames”?

    Thanks!

    Thread Starter mevelardi

    (@mevelardi)

    Hi @wfasa,
    thank you for following up. The problem was previously cleared by cleaning the cache, however today it re-presented itself even worse I was just trying to login via wp-admin and it immediately locks me out, without even going to the login page. I will have to delete it from the backend. Answering to your question I usually give at least 5 attempts, no I only have immediately lock out user trying to login with username admin.

    Thank you!

    Thread Starter mevelardi

    (@mevelardi)

    I uninstalled, reinstalled, cleared cache and on logout I got locked out again. I didn’t touch any of the settings.this is the logout url https://steams3000.com/wp-login.php?action=logout&_wpnonce=ba48e614fc
    Thanks!

    Thread Starter mevelardi

    (@mevelardi)

    I also tried unistalling and reinstalling the waf file, whitelisting my IP address nothing, I always get the locked out screen but if I go back in the browser I’m in again …

    Hi @mevelardi,

    Which cache are you using? I’m not 100% sure just yet but it sounds like the cache might be caching the block page and serving it to everyone?

    Thread Starter mevelardi

    (@mevelardi)

    HI @wfasa,
    we’re using WP SuperCache.
    Thanks,

    Hi @mevelardi!

    Thanks for that information. I’m not aware of any current problems like this with WP SuperCache so that may not be it then.

    Can you please check to make sure Wordfence is set to get IPs correctly? In Wordfence “All Options” look for “General Wordfence Options”. Find the text that says “Your IP with this setting:” and make sure the IP that is displayed there is your own IP. You can find out which IP you have by typing for example “My IP” in Google.

    Thread Starter mevelardi

    (@mevelardi)

    Hi @wfasa,
    yes Ip is read correctly. Can it be an SSL problem? We recently moved hosting and we had to rekey the SSL
    Thanks!

    Hi @mevelardi,
    I don’t think it should be the SSL itself. However, if you have set up redirects for http to https that could possibly be related. Do you know how the http > https redirect is being done? Typically it could be in .htaccess or it could also be a plugin doing it in WordPress.

    You should be able to see if this is a redirect issue by reproducing the scenario (log out and get blocked) while keeping a browser console open. Look at the requests and see if there are any 301 or 302 happening.

    Also make sure your site URLs in WordPress settings are all https and not http.

    Hi @mevelardi,
    Since we haven’t heard from you for a while I’m going to go ahead and resolve this thread for now. If you have any other questions or concerns at any point, feel free to start a new thread. Thank you!

    Thread Starter mevelardi

    (@mevelardi)

    Hi @wfasa,
    the issue is still there I disabled wordfence for the time being as we needed to go live.
    Thanks,

    Hi @mevelardi,
    Thanks for the update. If it’s possible to enable Wordfence at any point, you could send me a diagnostics report from Wordfence. The function to send diagnostics is at the top of the Wordfence > Tools > Diagnostics. If so, make sure you send it to [email protected] and enter your username mevelardi so I know who the diagnostics are coming from.

    Thanks!

Viewing 12 replies - 1 through 12 (of 12 total)
  • The topic ‘Wordfence locks out on Woocommerce account logout’ is closed to new replies.