Skip to content

Add or edit CAPTCHA-protected URLs

cPFence v4+ CAPTCHA uses a server-level list of protected URL paths.

CAPTCHA protected URLs selected in Edit Configuration Files, with its path and Save changes.

The server-level CAPTCHA path list. File contents are concealed for privacy, not shown as an empty or default list. Select the image for full size; use browser Back to return.
  1. Choose the target server and disable its WAF master for editing.
  2. Open Edit Configuration Files → CAPTCHA protected URLs.
  3. Add or remove one path per line in File content, preserving entries you still need. Examples include /wp-login.php and /custom-admin/login.
  4. Choose Save changes, read the result and reload to verify the list.
  5. Enable WAF again and confirm the required global/domain CAPTCHA switches.

Support users need file-editing and WAF-control permissions. The installed list is /etc/cpfcli/waf/userdata_login_pages; use the validated editor where possible.

If a legitimate login stops working, restore the prior path list through the same workflow and review the matching event. Do not disable every domain’s protection to hide one path problem.