logo

Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities

ID: 5860e199-4a98-54e9-9ded-324eca6ddcc0

STIX ID: report--5860e199-4a98-54e9-9ded-324eca6ddcc0

Feed Name: Cloudflare Blog

Threat Score
75/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Daniele Molteni

...
...

**Cloudflare deployed WAF protections (deployed 2026-07-17 17:03 UTC) to block exploitation of two critical WordPress vulnerabilities — CVE-2026-60137 (SQL injection, affects WordPress 6.8+) and CVE-2026-63030 (unauthenticated RCE, affects WordPress 6.9+) — and recommends updating to WordPress 7.0.2 or the listed backports (6.9.5, 6.8.6, 7.1 Beta 2).** The release lists Cloudflare rule IDs (managed and free rulesets), notes default Block actions, urges customers to enable Managed Rules or confirm Free Ruleset protection, review overrides that change Block to Log, and monitor security events while patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.