Skip to main content
Products Security

Cloudflare deploys WAF rules for two critical WordPress vulnerabilities

Cloudflare deploys WAF rules for two critical WordPress vulnerabilities Image: Primary
Cloudflare has deployed Web Application Firewall protections for two critical vulnerabilities affecting WordPress sites. The rules, pushed at 17:03 UTC on July 17 2026, cover all customers whose traffic is proxied through Cloudflare's WAF, including free-plan users. The vulnerabilities affect different components: CVE-2026-60137 is a high-severity SQL injection in WordPress 6.8 and later; CVE-2026-63030 is a critical unauthenticated remote code execution flaw in WordPress 6.9 and later that can be triggered via the REST API batch endpoint when a persistent object cache is not in use. The RCE vulnerability is related to the SQL injection issue and requires no authentication or user interaction. WordPress released fixes in version 7.0.2 with backports to 6.9.5, 6.8.6, and 7.1 Beta 2. Versions prior to 6.8 are not affected. WordPress is treating this as its highest-severity class of issue and is forcing automatic updates to affected sites. Cloudflare emphasizes that WAF protections reduce exposure while customers update but are not a substitute for applying the patches.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Cloudflare Blog and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Capital
AI Capital

Anthropic IPO preparation pressures US listing calendar

Anthropic is preparing to file publicly for an initial public offering in the coming weeks, Bloomberg reported. The prospective listing is expected to raise as much as SpaceX's record $86.2 billion debut, if not more. Companies pl...

AI Products
AI Products

SpaceX reportedly agrees to acquire Cursor developer Anysphere

SpaceX has agreed to acquire Anysphere, the company behind AI coding platform Cursor, in a transaction valued at $60 billion, according to the Times of India article. The article says SpaceX had an option, announced in April, to ...

Products
Products

AWS signs deal to acquire DuckDB developer DuckLabs

Amazon Web Services said it has signed a definitive agreement to acquire Amsterdam-based DuckLabs, the company behind DuckDB, an open-source analytical database. AWS said DuckDB will remain open source under its independent founda...

Security AI
Security AI

Researchers link Aurora ransomware activity to Cursor AI agent use

CloudSEK and Gambit Security reported that operators associated with Aurora ransomware used Cursor's agentic coding tools while working against victim networks. Gambit said it observed Cursor Agent running Anthropic's Claude Sonne...

Infrastructure Policy
Infrastructure Policy

India seeks second commercial chip fab under Semicon 2.0

India's IT ministry is inviting global technology companies to build a second commercial silicon chip fabrication plant under its Semicon 2.0 programme, with a target for operation by 2031. The programme offers up to 40% cash ince...