Scanner says core files were modified? Open the diff. After wp2shell, that is often leftover access.

How to read it

Developers

Filter wf_sn_trusted_proxy_cidrs

Add or change the CIDR list Automatic visitor IP detection trusts for reverse proxies that are not Cloudflare.

Visitor IP detection in Automatic mode trusts Cloudflare proxy ranges by default. For another load balancer or reverse proxy, you add its IPs under Trusted proxy CIDRs on Firewall → Settings.

The wf_sn_trusted_proxy_cidrs filter runs after that list is sanitized (invalid lines and open ranges such as 0.0.0.0/0 are already removed). Use it to add ranges from code instead of the settings field, or to merge a shared list across sites.

User-facing guide: Visitor IP detection.

Filter signature

apply_filters( 'wf_sn_trusted_proxy_cidrs', $cidrs );
ParameterTypeDescription
$cidrsstring[]Sanitized CIDR or single-IP entries from settings

Return an array of CIDR or IP strings. Keep the list short and specific. The settings field caps stored entries at 32. The filter can add more, but each extra range widens who can present X-Forwarded-For or X-Real-IP in Automatic mode.

Example: trust an internal load balancer

add_filter( 'wf_sn_trusted_proxy_cidrs', function ( $cidrs ) {
    $cidrs[] = '203.0.113.10/32';
    $cidrs[] = '198.51.100.0/24';
    return array_values( array_unique( $cidrs ) );
} );

Only add IPs your own proxy uses to reach PHP. Do not trust client-supplied headers on the public internet.

To override the resolved visitor IP after detection runs, use wf_sn_client_ip.

Not sure how to add this code? See Add custom code to your website.

Still stuck? Get help or contact us.

Larger screenshot

Enlarged image