Website Security & Threat Management
Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities

Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities

7/17/2026 · Daniele Molteni, Ah-young Choi, Georgie Yoxall, Kuber Nandwani, Vikram Grover

What this post added

This post details the deployment of two new Cloudflare WAF Managed Rules to protect against CVE-2026-60137 (SQL Injection) and CVE-2026-63030 (Unauthenticated Remote Code Execution) vulnerabilities in WordPress. It outlines the specific rule IDs, default actions (Block), and the technical mechanisms by which these rules detect and mitigate the attacks by inspecting crafted parameter values and targeting the REST API batch endpoint. The post also emphasizes that these rules are a defense-in-depth measure and not a replacement for patching the underlying WordPress software.

Read the original post ↗