<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cloudflare-waf-protects-wordpress-applications-from-two-high-severity-vulnerabilities-ywosrnqeb" -->

---
title: Cloudflare WAF protects WordPress applications from two...
description: Cloudflare has deployed two WAF rules to protect WordPress sites from two high-severity vulnerabilities disclosed by the WordPress security team before public...
canonical: https://daily.dev/posts/cloudflare-waf-protects-wordpress-applications-from-two-high-severity-vulnerabilities-ywosrnqeb
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities | daily.dev
og:description: Cloudflare has deployed two WAF rules to protect WordPress sites from two high-severity vulnerabilities disclosed by the WordPress security team before public...
og:url: https://daily.dev/posts/cloudflare-waf-protects-wordpress-applications-from-two-high-severity-vulnerabilities-ywosrnqeb
og:image: https://api.daily.dev/og/posts/YwosRnQEB.png
og:image:alt: Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities

**[Cloudflare](https://daily.dev/sources/cloudflare)** · 4 min read · 0 upvotes · 0 comments

## Summary

Cloudflare has deployed two WAF rules to protect WordPress sites from two high-severity vulnerabilities disclosed by the WordPress security team before public release. CVE-2026-60137 is a SQL injection flaw affecting WordPress 6.8 and later, while CVE-2026-63030 is an unauthenticated RCE vulnerability via the REST API batch endpoint affecting WordPress 6.9 and later. Both rules are active in Block mode for all Cloudflare customers, including free plan users. WordPress has released patches in versions 7.0.2, 6.9.5, 6.8.6, and 7.1 Beta 2, with automatic updates being forced for affected sites. WAF protection is a temporary mitigation — updating WordPress remains the recommended fix.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://blog.cloudflare.com/wordpress-vulnerabilities>

---

Tags: [#security](https://daily.dev/tags/security), [#sql](https://daily.dev/tags/sql), [#wordpress](https://daily.dev/tags/wordpress), [#cloudflare](https://daily.dev/tags/cloudflare)

[View this post on daily.dev](https://daily.dev/posts/cloudflare-waf-protects-wordpress-applications-from-two-high-severity-vulnerabilities-ywosrnqeb)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities","url":"https://daily.dev/posts/cloudflare-waf-protects-wordpress-applications-from-two-high-severity-vulnerabilities-ywosrnqeb","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cloudflare-waf-protects-wordpress-applications-from-two-high-severity-vulnerabilities-ywosrnqeb"},"datePublished":"2026-07-17T20:23:19.991Z","dateModified":"2026-07-20T13:33:39.074Z","description":"Cloudflare has deployed two WAF rules to protect WordPress sites from two high-severity vulnerabilities disclosed by the WordPress security team before public...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5c6b4a33e897adb791520e35b2886bcc?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5c6b4a33e897adb791520e35b2886bcc?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Cloudflare","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Cloudflare","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/38522e1d11354cd6b7af66f9d4316735","url":"https://daily.dev/sources/cloudflare"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/cloudflare-waf-protects-wordpress-applications-from-two-high-severity-vulnerabilities-ywosrnqeb","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,sql,wordpress,cloudflare","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Cloudflare","item":"https://daily.dev/sources/cloudflare"},{"@type":"ListItem","position":3,"name":"Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities"}]}
```

