Back Issues This Week → Calendar → Current Issue → Popular →

All issuesVolume 340, Issue 3IT Vendor NewsCloudflare

Cloudflare WAF Protects WordPress Applications From Two High-Severity Vulnerabilities

Cloudflare, Friday, July 17th, 2026

Cloudflare deployed WAF rules protecting all customers against two newly disclosed high-severity WordPress flaws.

Cloudflare rolled out Web Application Firewall rules covering CVE-2026-60137, a high-severity SQL injection affecting WordPress 6.8 and later, and CVE-2026-63030, a critical unauthenticated remote code execution flaw in the REST API batch endpoint in WordPress 6.9 and later.

The rules were deployed automatically to all Cloudflare users, including those on free plans. WordPress issued patches in versions 7.0.2, 6.9.5, 6.8.6, and 7.1 Beta 2, with automatic updates forced for affected sites.

Cloudflare stresses that WAF coverage is interim protection and that updating WordPress remains the most effective remediation. Customers are advised to confirm they run a patched version and that the WAF rules remain active in blocking mode.

more →  ·  More from Cloudflare →