I could see that you have set “Block Threshold” value to 2. We recommend to set it to minimum 20, as 2 is too small and most of the valid requests might reach that value. And that’s why the bing visitors are also banned.
The aim of HMWP IDS is to block malicious requests It detects Cross-site scripting (XSS), SQL injection, header injection, Directory traversal, Remote File Execution, Local File Inclusion, Denial of Service (DoS).
These requests are malicious as impact level is high – https://www.screencast.com/t/ojKZ4zXDR9C7
Besides IDS, HMWP hides wordpress so that’ll prevent from malicious scripts intended for wordpress sites.