ELSEIF
Your brief EB
183 stories from 71 feeds 32 clusters Refreshed 8 minutes ago next pull 13:20

INFRA Signal 203

Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities

WHY IT MATTERS

If you operate WordPress sites behind Cloudflare, you have interim protection at the edge, but you still need to patch — the WAF rules do not fix the underlying vulnerable code. The RCE (CVE-2026-63030) is particularly urgent because it requires no authentication or user interaction to exploit, targeting the REST API batch endpoint when a persistent object cache is not in use.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

CVE-2026-63030 is a critical unauthenticated RCE affecting WordPress 6.9 and later via the REST API batch endpoint, and CVE-2026-60137 is a high-severity SQL injection affecting WordPress 6.8 and later; versions earlier than 6.8 are not affected.

02

Cloudflare deployed blocking WAF rules for both vulnerabilities on July 17 2026, protecting all proxied customers including those on free plans, but customers who override ruleset actions from Block to Log should verify the new rules use the recommended action.

03

WordPress has released fixes in version 7.0.2 with backports to 6.9.5, 6.8.6, and 7.1 Beta 2, and is forcing automatic updates on affected sites — operators should confirm their sites are on a patched release.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Cloudflare Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities Open ↗