I recently started seeing a bunch of probably malicious requests (probing for wordpress plugins on my lemmy host) coming from Cloudflare IP addresses. I do use Cloudflare for my nameservers, but the records are set to DNS only (not Proxy).
These requests all come from a Cloudflare IPv4, with 2a06:98c0:3600::103 as the X-Forwarded-For header, which VirusTotal also attributes to Cloudflare. There is nothing else in the X-Forwarded-For chain.
Does anyone know what is going on or have any hypothesis ?


Since your records are DNS-only, these requests hit your origin directly, so you can deal with them there no matter who is behind the Worker. A Lemmy host has no WordPress, so anything asking for /wp-login.php, /wp-content/ or /xmlrpc.php is junk. Two cheap fixes: have your reverse proxy reject those paths outright, or use CrowdSec with its WordPress/http-probing scenarios, which bans the source after a few hits.