How to Add or Edit Captcha WAF Protected URLs?

cPFence’s Captcha WAF module lets you define exactly which login pages and other paths are protected by CAPTCHA checks. You can update this list via the WebUI or by editing the configuration file through the CLI.

Using the WebUI

  1. Open the cPFence WebUI on your Main Control Panel server and select Edit Configuration FilesEdit Captcha Protected URLs.
  2. In the list that appears, add each URL path you want protected on its own line (for example, /wp-login.php or /custom-admin/login) or remove any paths you no longer need.
  3. Click Save to apply your changes.

Restart the Web Server

To apply these changes, restart your web server:

systemctl restart nginx.service
systemctl restart apache2.service
systemctl restart lshttpd.service

CLI Options

You can also manage the protected URLs directly on the server:

nano /opt/cpfence/app/cpfwaf/userdata_login_pages

Add or remove one URL path per line. For example:

/wp-login.php
/wp-admin
/custom-admin/login
/my-custom-login.php

Save the file (Ctrl + O) and exit (Ctrl + X).

Restart the Web Server

To apply these changes, restart your web server:

systemctl restart nginx.service
systemctl restart apache2.service
systemctl restart lshttpd.service

Need Further Assistance?

If you encounter any issues or need additional help, feel free to reach out to our support team via your client portal.

  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

Why my custom WAF rules are not working?

If your custom ModSecurity rules aren’t taking effect, it’s often due to duplicate rule IDs or...

How to Block or Whitelist Certain User Agents ?

This guide will help you block or whitelist specific user agents in cPFence. You can manage these...

How to Enable / Disable WAF Rule by ID ?

This guide provides instructions for enabling and disabling specific WAF (Web Application...

How to Enable / Disable WAF?

The cPFence Web Application Firewall (WAF) now fully supports Apache, Nginx, OLS, and LSWS web...

How to Identify Problematic WAF Rule IDs in cPFence?

New! You can now use an automatic tracking tool to identify problematic WAF rules in real time....