Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

If Cloudflare is caching a WordPress login, account, cart, checkout, or other personalized page, the likely problem is that a broad cache rule makes dynamic HTML eligible for caching, a needed bypass does not match the request, or a later rule overrides the bypass. Check the actual path, cookies, response headers, and every matching rule before disabling caching site-wide. Cloudflare’s WordPress guidance describes edge caching for anonymous page views while bypassing cache for logged-in visitors and WooCommerce activity (Cloudflare’s WordPress performance guidance).

Why Cloudflare can cache a dynamic WordPress page

WordPress does not automatically make every response uncacheable. Cloudflare can cache HTML through Automatic Platform Optimization (APO) when the request and response meet APO’s eligibility conditions. Those conditions include the request method, HTML content, plugin header, cookies, headers, path, query string, and applicable Page Rules. A custom Cache Rule can also make dynamic HTML eligible, so do not assume that a page is protected just because it is part of WordPress.

Cloudflare’s recommended pattern is to cache eligible anonymous page views while bypassing personalized or authenticated responses. The problem often arises when a broad “eligible for cache” rule or an Edge TTL override applies to a route that needs to set or use a session cookie. Cloudflare describes a case where a cacheable login response may have its Set-Cookie header removed before storage; the browser then lacks the session cookie needed for the next request. See Cloudflare’s guidance on dynamic content and login issues.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which WordPress paths should bypass cache?

Start with the routes that display or process user-specific information. Cloudflare names login, account, cart, and checkout paths as examples to bypass when they serve dynamic or authenticated HTML. The exact URLs vary by site, so check your WordPress and plugin routes rather than copying a path list blindly.

  • Login and authentication pages, including any custom login URL.
  • Account or profile pages that show a signed-in user’s information.
  • WooCommerce cart and checkout pages.
  • Application API or form-processing routes that return personalized content or set session cookies.

Cloudflare’s recommendations and examples are in its dynamic-content troubleshooting guide. A route exclusion only helps when its expression matches the host and path that the browser actually requests.

How APO cookies and query strings affect caching

Cookie behavior is feature-specific

Cloudflare’s WordPress guidance describes bypassing edge cache when a visitor logs in or adds an item to WooCommerce. APO also documents cookie-prefix behavior: cookies with listed prefixes, including wordpress and woocommerce_, always bypass APO cache. These are protections documented for the relevant Cloudflare WordPress/APO behavior, not a guarantee that every custom Cache Rule will bypass when those cookies appear.

For a custom Cache Rule, explicitly match the Cookie field and set Cache eligibility to Bypass cache where appropriate. Cloudflare provides an example in its Bypass Cache on Cookie instructions and explains the available settings in its Cache Rules settings reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

APO treats most query strings as a reason to bypass

APO generally bypasses cache for URLs with query parameters unless the parameters are on its supported marketing-parameter allowlist. The published list includes attribution parameters such as utm_source, utm_campaign, and gclid. A site-specific parameter that changes page content is not harmless tracking metadata; ensure it does not cause personalized or otherwise distinct content to be served from an inappropriate cache entry. These query-string details apply to APO and should not be generalized to custom Cache Rules. See APO’s query-parameter reference and About Automatic Platform Optimization.

Check rule order, not just the bypass expression

Cloudflare Cache Rules can stack. When multiple matching rules set the same setting, the last matching rule wins. A correctly written bypass can therefore be undone by a later, broader rule that makes the response cache-eligible. Review all rules matching the same hostname and path, including legacy Page Rules, and inspect their order. Cloudflare documents this behavior in its Cache Rules order and priority reference.

How to diagnose and fix a cached login or account page

  1. Reproduce the exact request. Test the affected URL as an anonymous visitor and in the logged-in or form-submission state that triggers the issue. Include the actual hostname, path, and query string.
  2. Inspect the response headers. Check CF-Cache-Status, Set-Cookie, and the origin’s Cache-Control headers. For a login response that should establish a session, a cached response paired with a missing expected Set-Cookie is a strong clue that caching is interfering.
  3. Review every applicable rule. Check cache eligibility, Edge TTL or status-code TTL overrides, cookie and path matches, and rule ordering. Include any legacy Page Rule that may affect the same request.
  4. Add or correct narrow bypasses. Exclude the site’s actual dynamic paths and, where necessary, requests carrying the relevant session or commerce cookies. Remove TTL overrides that force caching when the origin must control the response. Preserve caching for anonymous static or otherwise safe content instead of turning it off across the whole site.
  5. Retest the affected behavior. Confirm that the response preserves the expected session-cookie behavior and does not serve personalized content from cache. Interpret the cache status using the distinctions below.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What CF-Cache-Status means for this problem

Header value or symptom What it indicates What to check
DYNAMIC Cloudflare determined at request time that the asset was not eligible for a cache lookup. Use it to distinguish an ineligible request from one that was eligible but not stored. Cloudflare’s definition is in its cache responses reference.
BYPASS The request may have been eligible, but the response or its cache-control instructions prevented storage. Inspect origin response headers and the rule behavior; do not interpret this as identical to DYNAMIC.
HIT or EXPIRED on a login response, with the expected Set-Cookie missing Potential evidence that a cacheable login response is interfering with session creation. Check the matching Cache Rules and TTL overrides, then verify the session flow after changing the bypass.

Cloudflare’s troubleshooting guidance recommends checking cache status and whether the expected session cookie is missing. A single status value is not a substitute for testing the route’s actual behavior: verify both anonymous and authenticated requests after the rule change.

Best Value
hosting servers
  • easy to use
  • Free app
  • Compatible with all devices
  • It gives the best comparison between ten different hosts

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.