Cloudflare's WAF Attack Score of Attack (not Likely Attack, but just simply Attack) is giving me false positives, and that was a bit unexpected. I had to create a Rate limiting rule based on he WAF Attack Score so that it only blocks if the number of requests exceeds 5 in 10 minutes, and then block for a day.
Just venting, I suppose :)