Skip to content
GravityKit
Buy
Sign in
0 items
  • Plugins

    GravityKit All Access

    Our complete Kit of essential tools for extending and enhancing Gravity Forms—everything you need to build powerful web apps and workflows.

    Learn more
    • GravityView

      GravityView

      Bestseller

      Display Gravity Forms entries on the front-end of your site and build powerful web applications.

    • GravityImport

      GravityImport

      Trending

      Import entries from CSV files into Gravity Forms to transfer data, create new forms, or update existing entries.

    • GravityEdit

      GravityEdit

      Quickly edit Gravity Forms entries inline to save time, reduce clicks, and streamline your workflow.

    • GravityCharts

      GravityCharts

      Trending

      Turn Gravity Forms entries into interactive charts and graphs.

    • GravityActions

      GravityActions

      Update multiple Gravity Forms entries at once, send bulk emails, and streamline your workflow.

    • GravityCalendar

      GravityCalendar

      Turn Gravity Forms entries into dynamic calendars to showcase events, schedules, appointments, and more.

    • GravityExport

      GravityExport

      Export Gravity Forms entries to Excel, CSV, PDF, or Google Sheets, then share them with secure links or deliver them to cloud storage on a schedule.

    • GravityMath

      GravityMath

      Perform advanced calculations on Gravity Forms entries to display totals, averages, or build custom calculators.

    • GravityRevisions

      GravityRevisions

      Track, compare, and restore changes made to Gravity Forms forms and entries with a full version history.

    • GravityMigrate

      GravityMigrate

      Migrate all Gravity Forms data, including forms, entries, Views, feeds, uploads, and more.

    • GravityBoard

      GravityBoard

      Manage projects with collaborative project management. Coordinate with your team and streamline your workflows.

    • GravitySearch

      GravitySearch

      Search Gravity Forms entries across every form from one screen.

  • Ideal For

    • Nonprofits
    • Web Agencies
    • Education
    • Developers
    • Small Businesses
    • Startups
    Explore All Use Cases

    Case studies

    • West Fork Schools
    • Princeton University
    • BrightLeaf Giving
    • Jacksonville Port Authority
    • National Severe Storms Lab
    • Leadpal
    • Mediebruket
    • Dragonfly
    View All Case Studies
  • Resources

    • Blog
    • Case studies
    • Newsletter
    • GravityKit vs competitors
    • Live Demos
    • Documentation
    • Developer docs
    • GravityKit Academy

    Ultimate guides

    • How to use Gravity Forms
    • Editing Gravity Forms entries
    • Importing Gravity Forms entries
    • Exporting Gravity Forms entries
    • Displaying Gravity Forms entries
    • Gravity Forms conditional logic
    • Gravity Forms calculations
    View More Articles
  • Plugins

    • GravityView

      GravityView

      Bestseller

      Display Gravity Forms entries on the front-end of your site and build powerful web applications.

    • GravityImport

      GravityImport

      Trending

      Import entries from CSV files into Gravity Forms to transfer data, create new forms, or update existing entries.

    • GravityEdit

      GravityEdit

      Quickly edit Gravity Forms entries inline to save time, reduce clicks, and streamline your workflow.

    • GravityCharts

      GravityCharts

      Trending

      Turn Gravity Forms entries into interactive charts and graphs.

    • GravityActions

      GravityActions

      Update multiple Gravity Forms entries at once, send bulk emails, and streamline your workflow.

    • GravityCalendar

      GravityCalendar

      Turn Gravity Forms entries into dynamic calendars to showcase events, schedules, appointments, and more.

    • GravityExport

      GravityExport

      Export Gravity Forms entries to Excel, CSV, PDF, or Google Sheets, then share them with secure links or deliver them to cloud storage on a schedule.

    • GravityMath

      GravityMath

      Perform advanced calculations on Gravity Forms entries to display totals, averages, or build custom calculators.

    • GravityRevisions

      GravityRevisions

      Track, compare, and restore changes made to Gravity Forms forms and entries with a full version history.

    • GravityMigrate

      GravityMigrate

      Migrate all Gravity Forms data, including forms, entries, Views, feeds, uploads, and more.

    • GravityBoard

      GravityBoard

      Manage projects with collaborative project management. Coordinate with your team and streamline your workflows.

    • GravitySearch

      GravitySearch

      Search Gravity Forms entries across every form from one screen.

    View All Products

    GravityKit All Access

    Our complete Kit of essential tools for extending and enhancing Gravity Forms—everything you need to build powerful web apps and workflows.

    Learn more
  • Ideal For

    • Nonprofits
    • Web Agencies
    • Education
    • Developers
    • Small Businesses
    • Startups
    Explore All Use Cases

    Case studies

    • West Fork Schools
    • Princeton University
    • BrightLeaf Giving
    • Jacksonville Port Authority
    • National Severe Storms Lab
    • Leadpal
    • Mediebruket
    • Dragonfly
    View All Case Studies

    How to build...

    • Property Management
    • Product Catalog
    • Fundraising Dashboard
    • Real Estate Directory
    • Document Library
    • Academic Journal
    • Volunteer Management
    • Meal Tracker
    View All Guides
  • Resources

    • Blog
    • Case studies
    • Newsletter
    • GravityKit vs competitors
    • Live Demos
    • Documentation
    • Developer docs
    • GravityKit Academy

    ultimate guides

    • How to use Gravity Forms
    • Editing Gravity Forms entries
    • Importing Gravity Forms entries
    • Exporting Gravity Forms entries
    • Displaying Gravity Forms entries
    • Gravity Forms conditional logic
    • Gravity Forms calculations
    View More Articles
  • Support
  • Pricing
0 items

Search

Results appear automatically as you type.
Loading results…

results found matching

    Sign in
    Buy

    Docs

    • Docs Home

    Gravity Forms Add-Ons

    • GravityView
    • GravityActions
    • GravityBoard
    • GravityCalendar
    • GravityCharts
    • GravityEdit
    • GravityExport
    • GravityImport
    • GravityMath
    • GravityMigrate
    • GravityRevisions
    • GravitySearch
    • GF Widget for Elementor
    • GF Dynamic Lookup
    • GF Entry Tags
    • GF Event Field
    • GravityExport Lite
    • GF Zero Spam

    GravityView

    • Getting Started
    • View Setup
    • FAQ
    • Pre-Sale
    • Advanced
    • Common Problems
    • Customizing Your Views
    • Edit Entry
    • Entry Approval
    • Filter and Sort Results
    • Gravity Forms
    • Merge Tags
    • Roles and Capabilities
    • Search
    • Shortcodes
    • View Settings
    • WordPress Posts

    General Help

    • Account, Invoices, and Billing
    • License Related
    • Plugins and Settings
    • Contact
    • Docs Home
    • Gravity Forms Add-Ons

      • GravityView
      • GravityActions
      • GravityBoard
      • GravityCalendar
      • GravityCharts
      • GravityEdit
      • GravityExport
      • GravityImport
      • GravityMath
      • GravityMigrate
      • GravityRevisions
      • GravitySearch
      • GF Widget for Elementor
      • GF Dynamic Lookup
      • GF Entry Tags
      • GF Event Field
      • GravityExport Lite
      • GF Zero Spam
    • GravityView

      • Getting Started
      • View Setup
      • FAQ
      • Pre-Sale
      • Advanced
      • Common Problems
      • Customizing Your Views
      • Edit Entry
      • Entry Approval
      • Filter and Sort Results
      • Gravity Forms
      • Merge Tags
      • Roles and Capabilities
      • Search
      • Shortcodes
      • View Settings
      • WordPress Posts
    • General Help

      • Account, Invoices, and Billing
      • License Related
      • Plugins and Settings
    • Contact

    General Help

      • Downloading a copy of your invoice
      • GravityKit W-9 Form (Tax ID)
      • Invoice information is incorrect
      • Nonprofit pricing
      • Refunds
      • Transferring your license
      • Turning off auto-renew subscriptions
      • Understanding Time-Based Proration for License Upgrades
      • Update your invoice with company name, address, or VAT number
      • Upgrading your license
      • Your GravityKit Account page
      • Managing Connected Sites
      • About the “GravityView + Extensions (Legacy)” license
      • Can’t deactivate license key
      • Development websites and GravityKit licenses
      • Downgrading your license
      • Granting GravityKit Support Access to Your Website
      • GravityKit pricing updates FAQ
      • Hard-coding your license key
      • Is PDF for GravityView included in All Access?
      • Managing GravityKit Products and Licenses via WP-CLI
      • Managing Your Licenses
      • Multisite and GravityKit Licenses
      • Products show as unlicensed
      • The license key keeps disappearing
      • Transferring your license
      • Upgrading your license
      • GravityKit code signing: technical overview
      • How to temporarily disable GravityKit plugins using a URL parameter
      • How to Get the Most Out of GravityKit Support
      • How to hide the “Function _load_textdomain_just_in_time was called incorrectly” notice
      • How To Import App Templates to Your Site
      • If you see a “This link has expired” or “Are you sure you want to do this?” message when installing a plugin
      • Installing standalone plugins
      • Installing, Activating, and Updating GravityKit Plugins
      • Locating and Updating Settings for GravityKit Products
      • Managing GravityKit Products and Licenses via WP-CLI
      • The “Download failed. Unauthorized” message
    • Home
    • Docs
    • General Help
    • Firewall or WAF blocking GravityKit imports and exports

    Firewall or WAF blocking GravityKit imports and exports

    Estimated reading: 9 minutes

    Updated on August 10, 2026

    If an import or export fails part-way through — or never starts — your site’s firewall may be blocking the request before it reaches WordPress. This article shows you how to confirm that, and how to fix it in Cloudflare, in a host-level firewall, and in security plugins like Wordfence.

    What you’ll see #

    The symptoms depend on which firewall is in the way, but they all look like the plugin failing for no reason:

    • A 403 Forbidden error when starting or running an export or import.
    • A Cloudflare block or challenge page instead of a response. The response has a cf-mitigated: challenge header.
    • “Server returned an empty response”.
    • The progress bar sits at 0%, or stops part-way and never resumes.
    • Your browser’s Network tab shows a failed POST to admin-ajax.php, or a failed request to a /wp-json/ URL.

    Why it happens #

    Imports and exports move your form and entry data between the browser and the server: an upload carrying a whole export file, or a run of requests carrying form definitions, settings and progress state. That data is ordinary content — but to a generic security rule it can look like an attack.

    Firewalls ship with SQL-injection rules that match words and characters common in real form data and in Gravity Forms settings: SELECT, UNION, CONCAT, quotes, parentheses, and so on. When one of those rules matches, the firewall blocks the request. WordPress never sees it, so the plugin has nothing to report beyond a 403 or an empty response.

    Nothing is wrong with your site or with the plugin. The request just needs to be allowed through.

    Step 1: Confirm the firewall is the cause #

    1. Open your browser’s Network tab (F12 → Network), then start the export or import again. Look for a request that returns 403 or fails.
    2. Check the response headers. A cf-mitigated header, or a Cloudflare block or challenge page in place of the response, means Cloudflare stopped it. A cf-ray header on its own does not — Cloudflare puts a Ray ID on every request it proxies, including successful ones. Use the Ray ID to look the request up, not as proof of a block.
    3. Check your logs. In Cloudflare, open your zone’s security events log and search by Ray ID to see exactly which rule fired. On other hosts, ask for your ModSecurity or firewall log for the time of the failure.
    4. Test with the firewall paused. If the export succeeds with the firewall off and fails with it on, you’ve confirmed it.

    If the Network tab shows no failing request at all, and an import simply stalls, this article is probably not your problem. A stalled background import usually means the site cannot make a loopback request to its own domain — background processing works by the server calling its own admin-ajax.php, and a firewall that blocks the server from reaching its own hostname stalls the run with nothing failing in your browser at all. Ask your host to allow the server to reach its own hostname, or set up a real system cron.

    Step 2: Know which requests to allow #

    Allow these specific requests, rather than opening up admin-ajax.php or the REST API as a whole:

    ProductRequest
    GravityMigrate — running an export or importPOST to /wp-admin/admin-ajax.php with action=gk_foundation_do_ajax. (This one action covers the gk_exporter, gk_importer and settings routers that the migration screens use.)
    GravityMigrate — uploading the import filePOST and DELETE to /wp-json/gk-foundation/v1/process-upload. Easy to miss: the entire export ZIP is sent in one POST, so this is the request a size or payload rule is most likely to kill.
    GravityImport — file upload and field mappingPOST to /wp-admin/admin-ajax.php with action=gv_import_entries_csv_upload, gv_import_entries_form_data, or gv_import_entries_add_form_field
    GravityImport — processing rows/wp-json/gravityview/import/v1/ and everything under it
    GravityBoard/wp-json/gravityboard/v1/ and everything under it — see Troubleshooting 403 errors in GravityBoard

    What you are actually allowing

    These endpoints are not all protected the same way, so allow only the rows for the product you are troubleshooting:

    • GravityMigrate, running an export or import — requires a logged-in user and a valid WordPress nonce. The nonce is issued to the logged-in user on the migration screen, so this is not reachable anonymously.
    • GravityMigrate, uploading the import file — additionally requires the manage_options capability, so administrators only.
    • GravityImport — requires the gravityforms_edit_entries capability. That is a Gravity Forms capability, which can be granted to non-administrator roles, and it is filterable.
    • GravityBoard — not an admin-only surface. Boards render on the front end, and each board’s own “who can view / add / edit” settings decide who may call these endpoints. A board set to Everyone (Including Logged-Out Users) is reachable by anonymous visitors with no nonce and no capability. Allowing these paths through your firewall exposes exactly whatever the board is already configured to expose — check the board’s settings before you allow it.

    Step 3: Fix it #

    Cloudflare

    Cloudflare’s Managed Ruleset is the usual culprit. Rather than turning rules off site-wide, add an exception (a skip rule) scoped as tightly as you can.

    Do not scope the exception on the Referer header. Anyone can set that header to any value, so a rule keyed on it would let a stranger skip your SQL-injection protection on admin-ajax.php just by sending the right string. Scope on your own IP address instead, and remove the exception when the migration is finished.

    1. In the Cloudflare dashboard, open your zone’s WAF managed rules (recent dashboards put this under Security; the exact menu labels have changed between dashboard versions).
    2. Find the blocked request in your zone’s security events log and note which rules fired. In one customer report these were three SQLi rules — SQLi – MultiLevel Function and two SQLi – String Function rules. Yours may differ, so read your own event log rather than copying these.
    3. Look up your current IP address (search “what is my IP”), then click Add exception and use an expression scoped to that address:
    http.host eq "www.example.com"
    and ip.src eq 203.0.113.45
    and http.request.method eq "POST"
    and (
      http.request.uri.path eq "/wp-admin/admin-ajax.php"
      or http.request.uri.path contains "/wp-json/gk-foundation/v1/process-upload"
    )
    1. Set the exception to skip only the specific rules you identified in step 2 — not the whole ruleset.
    2. Save, then run the export or import again.
    3. Delete the exception once the migration is done. It is meant to be temporary.

    Replace example.com with your own domain and 203.0.113.45 with your own IP address. If your IP changes (many home connections rotate daily), you will need to update the rule.

    For GravityImport, swap the process-upload path for /wp-json/gravityview/import/v1/.

    If a fixed IP is not workable — a whole office behind changing addresses, for example — then do not build a rule around a header instead. Disable the specific rule IDs that fired for the length of the migration and turn them back on immediately afterwards.

    Which managed rulesets you get depends on your Cloudflare plan, so the rule names in your Security Events may not match the examples above. Whatever plan you are on, add a narrowly scoped exception rather than switching a ruleset off — turning off the Managed Ruleset removes protection for every visitor to your site, not just for your migration.

    Host-level firewalls (ModSecurity and similar)

    You usually can’t change these yourself. Contact your hosting provider and give them:

    • The date and time of the failure, and your own IP address.
    • The URL that was blocked (/wp-admin/admin-ajax.php, or the /wp-json/ path from the table above).
    • A request to allowlist that path for your IP address, or to disable the specific rule IDs their log shows firing — and to revert the change once your migration is finished.

    Ask for the exception to be scoped to your IP, not to “logged-in administrators”. At the firewall layer there is no way to tell a real administrator from anyone who sends a WordPress-looking cookie, so a login-based rule is not the protection it sounds like.

    Most hosts can find the blocked request in their logs from the timestamp alone and will make a targeted rule change.

    Security plugins (Wordfence, NinjaFirewall, Sucuri, MalCare)

    Security plugins that inspect POST data can reject these requests for the same reason a WAF does. Check the plugin’s blocked-traffic log first to confirm it is the one blocking you, then either:

    • Allowlist the URL and action from the table above, using the plugin’s own allowlist setting. This is the targeted option and the one to prefer.
    • Or run the firewall in learning mode for a single import or export run. Be aware this stops the firewall blocking anything, for every visitor, for as long as it is on — which on a large migration can be hours. Switch it back to fully enabled the moment the run finishes.

    See your plugin’s own documentation for where these settings live — Wordfence’s firewall documentation covers allowlisting and learning mode.

    One note on Wordfence: with Extended Protection enabled, the firewall inspects requests before WordPress loads, so it can block something a WordPress-level rule would have allowed. Allowlisting is still done in the Wordfence dashboard as normal — you only need your host if Extended Protection itself has to be installed or removed.

    Step 4: Confirm it worked #

    Run the export or import again and watch the Network tab. The request that previously returned 403 should now go through. Don’t stop at the status code — a 200 only means the firewall let the request past, and our plugins can still return an error message inside a 200 response. Confirm the export or import actually reaches completion in the UI. Once the migration is finished, remove the exception you added.

    Still stuck? #

    Contact GravityKit support and include:

    • Which product and version you’re using.
    • The exact error message or a screenshot.
    • Your Cloudflare Ray ID, or the firewall log entry for the blocked request.
    • The name of your host and any security plugins you have active.

    Related articles #

    • Troubleshooting 403 errors in GravityBoard
    • Allowing GravityKit license checks through your firewall — for the opposite problem, where your server can’t reach GravityKit
    • Best practices to follow when moving data using GravityMigrate
    • Error: Server returned an empty response
    Still stuck? How can we help?

    How can we help?

    "*" indicates required fields

    This field is for validation purposes and should be left unchanged.
    Replies will go to this email.
    How can we help?*
    My pre-sale question is related to...*
    My WordPress skills are....*
    My Gravity Forms skills are...*
    You will be shown articles from our documentation.
    Vous pouvez nous écrire dans votre langue maternelle si c’est plus facile pour vous—nous nous occuperons de la traduction!
    Puedes escribirnos en tu idioma nativo si te resulta más fácil; ¡nosotros nos encargamos de la traducción!
    Sie können uns in Ihrer Muttersprache schreiben, wenn das für Sie einfacher ist – wir kümmern uns um die Übersetzung!
    U kunt ons in uw moedertaal schrijven als dat gemakkelijker voor u is — wij zorgen voor de vertaling!
    Du kan skrive til oss på ditt morsmål hvis det er enklere for deg — vi tar oss av oversettelsen!
    Du kan skriva till oss på ditt modersmål om det är lättare för dig — vi tar hand om översättningen!
    Você pode nos escrever em seu idioma nativo se for mais fácil para você — nós cuidaremos da tradução!
    Puoi scriverci nella tua lingua madre se ti è più facile — penseremo noi alla traduzione!
    Please provide as much detail as you're able; this helps us provide you with faster support.
    Drop files here or
    Accepted file types: jpg, jpeg, gif, png, tiff, pdf, bmp, zip, json, csv, xls, xlsx, Max. file size: 256 MB.
      Get better at Gravity Forms every Friday

      Was this page helpful?

      Table Of Contents
      • What you’ll see
      • Why it happens
      • Step 1: Confirm the firewall is the cause
      • Step 2: Know which requests to allow
      • Step 3: Fix it
      • Step 4: Confirm it worked
      • Still stuck?
      • Related articles
      GravityKit
      • How to Build It
      • GravityKit vs competitors
      • Pricing
      • Products
      • Our Team
      • Our Values
      • Work With Us
      • Coupons
      Support
      • Support
      • Contact
      • Documentation
      • Scope of Support
      • Brand Guidelines
      • Privacy Policy
      • Terms of Service (“Terms”)
      I am a...
      • Nonprofit
      • Web agency
      • Small business owner
      • Web developer
      • Educational institution
      • WordPress freelancer
      • Startup founder
      • One-person agency
      Get notified of updates.

      We’re constantly improving GravityKit. Fill out your email below and we’ll notify you anytime major updates drop.

      • Facebook
      • Twitter
      • Mastodon
      GravityKit is a Gravity Forms Certified Developer.

      Copyright © 2026, Katz Web Services, Inc.

      GravityKit and GravityView are registered trademarks of Katz Web Services, Inc.