Cloudflare WAF 防御 WordPress 应用程序的两个高危漏洞
Cloudflare 已针对 WordPress 安全团队向我们披露的两个高危漏洞部署了两条 WAF 规则。新规则可保护所有使用受影响 WordPress 版本的 Cloudflare 客户,但客户仍应立即进行更新……
Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities
详细说明
Blog CVE Vulnerabilities WAF +1 Show 1 more tags
4 Tags Show 4 tags
WordPress
CVE Vulnerabilities WAF WordPress
July 17, 2026
- Selected Tags
- CVE Vulnerabilities WAF WordPress
- All tags
- Matching tags
- No tags found
- 1.1.1.1
- 2FA
- Abuse
- Access
- Access Control Lists (ACLs)
- Accessibility
- Account Takeover
- Acquisitions
- Addressing
- Advanced Certificate Manager
- Advanced DDoS
- Advertising
- Aegis
- Africa
- Afroflare
- Agent Readiness
- Agents
- Agents Week
- AI
- AI Bots
- AI Gateway
- AI Search
- AI-SPM
- AI WAF
- AI Week
- Alertmanager
- Always Online
- AMD
- AMP
- Analytics
- Anonymous
- Anti Malware
- Anycast
- API
- API Gateway
- API Security
- API Shield
- APJC
- Apple
- Application Security
- Application Services
- Area 1 Security
- Argo Smart Routing
- ASCII
- Asia
- Athenian Project
- Atlassian
- Attacks
- Audit Logs
- Austin
- Australia
- Authentication
- Authy
- Automatic HTTPS
- Automatic Platform Optimization
- Automation
- AutoMinify
- Auto Rag
- Awards
- AWS
- Baidu
- Bandwidth Alliance
- Bandwidth Costs
- Best Practices
- Beta
- Better Internet
- BGP
- Birthday Week
- Blackbird
- Black Friday
- Bot Fight Mode
- Bot Management
- Botnet
- Bots
- BPF
- Brand
- Brand Protection
- Brazil
- Browser Insights
- Browser Rendering
- Browser Run
- Bug Bounty
- Bugs
- BYOIP
- Cache
- Cache Purge
- Cache Reserve
- Cache Rules
- California
- Canada
- Cap'n Proto
- CAPTCHA
- Careers
- CASB
- Categories
- CDN
- CDNJS
- Certificate Authority
- Certificate Pinning
- Certificate Transparency
- Certification
- CFSSL
- Challenge Page
- ChatGPT
- China
- China Network
- Christmas
- Chrome
- CIO Week
- CISA
- Claire
- CLI
- ClickHouse
- Clientless
- Clientless Web Isolation
- Cloud Connector
- Cloud Email Security
- Cloudflare Access
- Cloudflare Apps
- Cloudflare Area 1
- Cloudflare Calls
- Cloudflare Email Service
- Cloudflare for Campaigns
- Cloudflare for SaaS
- Cloudflare for Startups
- Cloudflare Gateway
- Cloudflare History
- Cloudflare Images
- Cloudflare Media Platform
- Cloudflare Meetups
- Cloudflare Network
- Cloudflare One
- Cloudflare One Client
- Cloudflare One User Risk Score
- Cloudflare One Week
- Cloudflare Pages
- Cloudflare Polish
- Cloudflare Queues
- Cloudflare Realtime
- Cloudflare Stream
- Cloudflare Tunnel
- Cloudflare TV
- Cloudflare Workers
- Cloudflare Workers KV
- Cloudflare Workers KV (ES)
- Cloudflare Workers (PT)
- Cloudflare Zero Trust
- Cloudforce One
- Cloudy
- Code Orange
- Coinbase
- Colombia
- Community
- Compliance
- Compression
- Config Rules
- Configuration Management
- Congestion Control
- Connectivity
- Connectivity Cloud
- Consumer Services
- Containers
- Content Independence Day
- Content Scanning
- Context
- Core
- COVID-19
- Crawler Hints
- CrowdStrike
- Cryptography
- Crypto Week
- CSAM Reporting
- Customers
- Customer Success
- Customer Zero
- CVE
- CVE-2023-50387
- Cyber Readiness
- Cybersecurity
- D1
- Dashboard
- Data
- Database
- Data Catalog
- Data Center
- Data Localization
- Data Localization Suite
- Data Loss
- Data Loss Prevention
- Data Platform
- Data Privacy Day
- Data Protection
- Data Sovereignty
- Data Transfer Bucket
- DDoS
- DDoS Alerts
- DDoS Reports
- Debugging
- Deep Dive
- Descaler
- Design
- Deskope
- Developer Documentation
- Developer Platform
- Developers
- Developer Spotlight
- Developers Storage
- Developer Week
- Device Security
- DevOps
- DEX
- Digital Experience Monitoring
- Digital Forensics
- Disrupt
- Distributed
- Distributed Systems
- Distributed Web
- Diversity
- DLP
- DMARC
- DNS
- DNS Filtering
- DNS Flood
- DNSSEC
- DNS Security
- Dogfooding
- DoH
- Domain Rankings
- Domain Scoped Roles
- dosd
- Drupal
- Due Process
- Durable Execution
- Durable Objects
- Early Hints
- Earth Day
- eBPF
- EC2
- eCommerce
- Edge
- Edge Computing
- Edge Database
- Edge Rules
- Education
- Egress
- Elastic
- Elections
- Election Security
- Elliptic Curves
- Email Routing
- Email Security
- Email Workers
- EmDash
- Emissions
- Employee Resource Groups
- Encrypted SNI
- Encryption
- Engineering
- Enterprise
- Entropy
- EPYC
- Ethereum
- Europe
- European Union
- Events
- Exploit
- Fancy Bear
- Fast Fonts
- FCC
- Feature Flags
- FedRAMP
- FedRAMP High
- FedRAMP Moderate
- Firefox
- Firewall
- Firmware
- Florida
- Football
- Formal Methods
- Forrester
- Fortran
- Foundation DNS
- Founders' Letter
- France
- Fraud
- Free
- Freedom of Speech
- Front End
- Full Stack
- Full Stack Week
- Fun
- Gartner
- Gatebot
- GA Week
- GDPR
- General Availability
- Generative AI
- Gen X
- Geo Key Manager
- Germany
- GitHub
- Go
- Google Analytics
- Google Cloud
- Google Workspace
- Government Innovation
- Grace Hopper
- Grafana
- GraphQL
- Green
- Grinch
- Growth
- gRPC
- Guest Post
- Hackathon
- Halloween
- Hardware
- HashiCorp
- Hertzbleed
- Heuristics
- History
- Holidays
- Holocaust
- Hong Kong
- Hosting Con
- Hostnames
- HTTP2
- HTTP3
- HTTPS
- Human Rights
- Hurricane
- Hybrid Cloud
- Hyperdrive
- IBM
- ICANN
- iCloud Private Relay
- Identity
- IETF
- IL4
- Image Optimization
- Image Recognition
- Image Resizing
- Image Storage
- Impact
- Impact Week
- I'm Under Attack Mode
- Incident Report
- Incident Response
- India
- Indicators of Compromise
- Indonesian
- Infrastructure
- Infrastructure as Code
- Insights
- Intel
- Interconnection
- Internal DNS
- Internet Performance
- Internet Quality
- Internet Regulation
- Internet Shutdown
- Internet Summit
- Internet Traffic
- Internet Trends
- Internship Experience
- Intrusion Detection
- Investors
- IoCs
- iOS
- IoT
- IPFS
- IPsec
- IPv4
- IPv6
- IRAP
- Israel
- Italy
- IWD
- JAMstack
- Japan
- JavaScript
- Jengo
- Jengo Policy
- Joomla
- Judeoflare
- Kafka
- Kernel
- Keyless SSL
- KeyTrap
- Key Value
- Killnet
- Korea
- Kubernetes
- LangChain
- Latency
- Latin America
- Latinflare
- LavaRand
- Lazarus group
- Leaked Credential Checks
- Legal
- Legal Patents Sable
- LGBTQIA+
- Life at Cloudflare
- Linux
- Lisbon
- Live Streaming
- Llama
- LLM
- Load Balancing
- Localization
- Log4J
- Log4Shell
- Logging
- Log Push
- Logs
- LUA
- Machine Learning
- Magecart
- Magic Firewall
- Magic Network Monitoring
- Magic Transit
- Magic WAN
- Magic WAN Connector
- Malicious JavaScript
- Malware
- Managed Components
- Managed Rules
- March of Cloudflare
- MASQUE
- MCP
- Meerkat
- MeetUp
- Meris
- Message Protocol
- Mexico
- Micro-frontends
- Microsoft
- Microsoft 365
- Microsoft Azure
- Middle East
- Migration Hub
- Milestones
- Miniflare
- Mirage
- Mirai
- Mitel
- Mitigation
- Mixed Content Errors
- MLops
- Mobile
- Mobile SDK
- Model Context Protocol
- Moldova
- Monitoring
- Multi-Cloud
- Multi-User
- MySQL
- NaaS
- Net Neutrality
- Network
- Networking
- Network Interconnect
- Network Performance Update
- Network Protection
- Network Services
- New Year
- NGINX
- Ninjas
- NIST
- Node.js
- North America
- Notebooks
- Notifications
- NSEC3
- OAuth
- Observability
- Oceania
- OCSP
- Offices
- Okta
- Olympics
- Onboarding
- OpenAI
- Open API
- OpenBMC
- OpenDNS
- Open Source
- OpenSSL
- OpenTelemetry
- Optimization
- Origin Rules
- Outage
- Oxy
- Pacific Northwest
- Page Rules
- Page Shield
- Parallels
- Partners
- Partnership
- Password-reuse
- Passwords
- Passwords (PT)
- Patents
- PAYGO
- Payments
- Pay Per Crawl
- PCI Certified
- Peering
- Performance
- Phishing
- php
- Phython
- Pingora
- Pipelines
- PlanetScale
- Plans
- Platform Engineering
- Platform Week
- Plesk
- Policy & Legal
- Politics
- Portugal
- Postgres
- Post Mortem
- Post-Quantum
- Precursor
- Prepared Statements
- Prisma
- Privacy
- Privacy Pass
- Privacy Week
- Private IP
- Private Network
- Product Design
- Product News
- Programming
- Programming (PT)
- Project Fair Shot
- Project Galileo
- Project Honey Pot
- Project Pangea
- Project Safekeeping
- Project Turpentine
- Prometheus
- Protocols
- Proudflare
- Proxying
- Public Sector
- Python
- Queues
- QUIC
- QUICHE
- Quicksilver
- R2
- R2 Super Slurper
- Radar
- Radar Alerts
- Radar API
- Radar Maps
- Railgun
- Randomness
- Ransom Attacks
- Rapid Reset
- Raspberry Pi
- Rate Limiting
- RC4
- RDDoS
- React
- Reading List
- Real-time
- Recruiting
- Regional Services
- Registrar
- Reliability
- Remote Browser Isolation
- Remote Desktop Protocol
- Remote Work
- Replication
- Research
- Resolver
- Restreaming
- Retreat
- Reverse Engineering
- REvil
- Risk Management
- Road to Zero Trust
- Rocket Loader
- RocksDB
- Routing
- Routing Security
- RPKI
- RRDNS
- RSA
- Russia
- Rust
- Rust Workers
- SaaS
- SAAS Security
- Sable
- Salt
- Sampling
- Sandbox
- SASE
- Save The Web
- SDK
- Search Engine
- Secrets Store
- Secure Web Gateway
- Security
- Security Analytics
- Security Center
- Security Posture
- Security Posture Management
- Security Service Edge
- security.txt
- Security Week
- SEO
- Serverless
- Serverless AI
- Serverless (PT)
- Serverless Week
- Server Push
- Servers
- SIEM
- Signed Exchanges (SXG)
- SIM
- Singapore
- Single Sign On (SSO)
- Smart Placement
- Smart Shield
- Snippets
- SOC as a Service
- South Africa
- South America
- Spain
- spdy
- Spectrum
- Speed
- Speed Brain
- Speed & Reliability
- Speed Week
- Spoofing
- Sports
- SQL
- SRE
- SSE
- SSH
- SSL
- Standards
- Startup Enterprise Plan
- Statistics
- StopTheHacker
- Storage
- Sumo Logic
- Super Bowl
- Supercloud
- Supply Chain Attacks
- Support
- Sustainability
- SWAG
- SWG
- Swift
- Switzerland
- SXSW
- SYN
- SYN Flood
- Syria
- TCP
- Team
- Teams Dashboard
- TechCrunch
- Technical Writing
- Tech Talks
- Terraform
- Testimonials
- Testing
- Texas
- Thanksgiving
- The Serverlist Newsletter
- Threat Data
- Threat Feeds
- Threat Intelligence
- Threat Operations
- Threats
- Tiered Cache
- TikTok
- TLS
- TLS 1.3
- Tools
- Tor
- Tracing
- Traffic
- Transform Rules
- Transparency
- Trends
- Trust & Safety
- TTFB
- TTL
- TURN
- TURN Server
- Turnstile
- TypeScript
- UDP
- Ukraine
- United Kingdom
- Universal SSL
- URL Scanner
- USA
- User Research
- VDI
- Vectorize
- Vetflare
- Video
- Visibility
- Vite
- VoIP
- VPC
- VPN
- Vulnerabilities
- WAF
- WAF Attack Score
- WAF Rules
- Waiting Room
- WARP
- WARP Connector
- WASM
- Web3
- Web Application Firewall
- WebAssembly
- Web Asset Discovery
- Webinars
- WebP
- WebRTC
- WebSockets
- Wildebeest
- Womenflare
- WordPress
- Workers AI
- Workers Launchpad
- Workers Logs
- Workers Observability
- Workers Sites
- Workers Unbound
- Workers VPC
- Workflows
- World IPv6 Day
- Wrangler
- x402
- Year in Review
- Z3
- Zaraz
- Zero Day Threats
- Zero Trust
- Zero Trust Week
- Zone Versioning
Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities
Daniele Molteni , Ah-young Choi , Georgie Yoxall , Kuber Nandwani , and Vikram Grover
3 minute read
COPY URL
Cloudflare has deployed new Web Application Firewall (WAF) protections for two critical vulnerabilities affecting WordPress. The protections address an Unauthenticated Remote Code Execution (RCE) vulnerability in WordPress's REST API and a related SQL Injection vulnerability.
The WordPress security team disclosed the vulnerabilities to Cloudflare before public release so that we could prepare protections for customers. Cloudflare has deployed the new rules to protect all customers, including those on free and paid plans, as long as their application traffic is proxied through the Cloudflare WAF. The rules were deployed at 17:03 UTC on July 17 2026.
WAF protections reduce exposure while customers update, but they are not a substitute for patching. WordPress has released fixes in version 7.0.2, with backports to affected earlier branches: 6.9.5, 6.8.6, and 7.1 Beta 2 ( see release details ). Versions earlier than 6.8 are not affected. WordPress is treating this as its highest-severity, highest-priority class of issue and is forcing automatic updates to affected sites, so most sites will be updated automatically. We still recommend confirming that you are on a patched release or the backports for your branch and follow the guidance in the official WordPress security release announcement .
What you need to know
The vulnerabilities affect different parts of the request path:
The SQL injection vulnerability is present from version 6.8 onwards, while the RCE only affects versions from 6.9. So 6.8.6 addresses the SQLi only since the RCE isn't present on 6.8, while 6.9.5, 7.0.2, and 7.1 Beta 2 get fixes for both.
Cloudflare created two rules to detect requests associated with these vulnerabilities:
Rule description
CVE
Rule ID for Managed Ruleset
Rule ID for Free Ruleset
Default action
Wordpress
CVE-2026-60137
1c060d3a371549219ee290d7ed933fcc
db003b39b7774859a8d588ce33697a1a
Block
Wordpress
CVE-2026-63030
7dfb2bd4708d4b88b9911dc0550664b6
ebd3f2df15c74ddcbf6220c9b5ec246a
Block
Cloudflare customers running WordPress sites on Pro, Business, or Enterprise plans should ensure that Cloudflare Managed Rules are enabled. Customers can follow the steps in our WAF Managed Rules documentation . Customers on free plans are automatically protected through the Free Ruleset.
The new rules are deployed with the default Managed Ruleset action of Block. Customers running WordPress sites should review any ruleset-level overrides, including those that change all rules from Block to Log, and ensure the new rules use the recommended action while they update WordPress. Cloudflare customers should also monitor Security Events for requests matching either rule.
- CVE-2026-60137: SQL injection. A vulnerability in WordPress version 6.8 and later allows crafted input to alter a database query. Rating High.
- CVE-2026-63030: Unauthenticated remote code execution. A vulnerability in WordPress version 6.9 and later allows an unauthenticated attacker to execute code through the batch endpoint of the REST API when a persistent object cache is not in use. This vulnerability is related to the SQL injection described above. No login or user interaction is required to exploit this vulnerability. Rating Critical.
- SQL Injection
- CVE:CVE-2026-60137
- Remote Code Execution
- CVE:CVE-2026-63030
Defense in depth while you patch
The SQL injection rule detects crafted parameter values before they reach WordPress. The unauthenticated RCE rule targets requests attempting to reach the remote code execution path. Together, they detect the attack at two different points.
These rules reduce risk while organizations update affected systems; they do not fix the underlying vulnerable code. Updating WordPress remains the most effective way to address the vulnerabilities.
If an immediate update is not possible, verify that both Cloudflare rules are active with the recommended action and review logs for suspicious requests to the affected REST API endpoint.
Looking forward
Cloudflare will monitor matching traffic and test the rules against new attack variations, updating detections when needed.
We thank the WordPress security team for coordinating with Cloudflare and other infrastructure providers to help protect users before details of the vulnerabilities became public.
Related tags
CVE Vulnerabilities WAF WordPress
Follow on Social Media
- Cloudflare