Cloudflare WAF Blocks Two Critical WordPress Vulnerabilities (CVE-2026-60137, CVE-2026-63030)
Cloudflare has deployed WAF rules to block a critical unauthenticated RCE and a high-severity SQL injection in WordPress. Patch now—versions 6.8 through 7.0.2 are affected.

Cloudflare pushed new WAF rules on July 17, 2026, to protect WordPress sites from two high-severity vulnerabilities that were disclosed to them ahead of public release. The rules are live for all Cloudflare customers, including free-tier users, as long as traffic is proxied through Cloudflare's WAF.
The Vulnerabilities
Two CVEs are in play:
- CVE-2026-60137 — SQL injection in WordPress 6.8 and later. Rated High.
- CVE-2026-63030 — Unauthenticated remote code execution via the REST API batch endpoint, affecting WordPress 6.9 and later. Rated Critical. No authentication or user interaction required. This one only works when a persistent object cache is not in use.
The SQLi is present from 6.8 onward; the RCE requires 6.9+. WordPress has released patches in versions 7.0.2, 6.9.5, 6.8.6, and 7.1 Beta 2. Automatic updates are being forced for affected sites, but you should verify you're on a patched release.
WAF Rules
Cloudflare deployed two rules, both defaulting to Block:
- SQLi rule ID:
1c060d3a371549219ee290d7ed933fcc(Managed) /db003b39b7774859a8d588ce33697a1a(Free) - RCE rule ID:
7dfb2bd4708d4b88b9911dc0550664b6(Managed) /ebd3f2df15c74ddcbf6220c9b5ec246a(Free)
Pro/Business/Enterprise users should ensure Cloudflare Managed Rules are enabled. Free users are automatically protected via the Free Ruleset. If you have any ruleset-level overrides that set rules to Log instead of Block, fix that now.
What You Should Do
WAF rules buy you time, but they're not a substitute for patching. Update WordPress to a fixed version immediately. If you can't patch right away, verify both rules are active and set to Block, and monitor Security Events for matching requests.
Cloudflare says it will continue monitoring traffic and update detections as new attack variations emerge.
Discussion
0 Comments
Be the first to start the discussion.