we_are_coded.by CODE · The world, decoded
БГ
Cloudflare

WordPress has a critical hole for remote code - Cloudflare raised a shield, but the patch won't wait

CloudflareSecurity

The WordPress core has two vulnerabilities, and the more severe one lets an unauthenticated attacker run their own code on the server. Cloudflare rolled out protective rules for all its customers on July 17, while the patches roll out. For anyone running a shop or site on WordPress, this is one of those things that won't wait until Monday.

In short
  • Two vulnerabilities in the WordPress core: SQL injection (high) and unauthenticated remote code execution (critical).
  • Cloudflare rolled out WAF rules for all plans on July 17, 2026 (17:03 UTC); the protection buys time, it doesn't replace the patch.
  • Patched versions: 7.0.2, 6.9.5, 6.8.6. Advice: check your version and update now, especially if it's a WooCommerce shop.
Checked on20 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

I checked ours before sitting down to write this. We run client shops on exactly this stack - WordPress behind Cloudflare - and this week two vulnerabilities dropped in the core at once.

The facts: on July 17, 2026, two vulnerabilities became public in the core of WordPress. The first, CVE-2026-60137, is a SQL injection (a way to slip a foreign command into the database) and affects WordPress 6.8 and up - rated high. The second, CVE-2026-63030, is the more severe one: an unauthenticated attacker - no password, no account - can run their own code on the server through a mass endpoint in the REST API, when the site has no persistent object cache. Rated critical. The patches ship in versions 7.0.2, 6.9.5, 6.8.6 (and 7.1 Beta 2). At 17:03 UTC the same day, Cloudflare rolled out managed WAF rules that stop these attacks for all its customers - on free and paid plans alike. According to Cloudflare, the protection lowers the risk while you update, but it isn't a substitute for the patch. Source: Cloudflare, blog on protecting WordPress applications, 17.07.2026.

That's why I read this as today's task, not as a headline. Cloudflare reacted fast and clean - a shield for everyone, hours after the holes went public, even on the free plans. That's the right move.

The shield stops the attack at the door. The patch closes the door itself. Don't mix them up.

Except the shield is a bandage, not a cure. It stops the known shape of the attack at the door; the patch closes the hole itself. It matters because the critical one of the two needs neither a password nor an account - it works down a list of addresses, not a specific target. And the uncomfortable truth about WordPress is that a huge share of sites update late or never.

We're pulling up the list of client WordPress and WooCommerce sites and checking the version. 6.8 and up - update to the patched one. Being behind Cloudflare makes us calmer, but calm isn't a patch. I know what someone will say. It works, why touch it. Those exact sites are on the automated attacker's list. You update today. Not on Monday.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Cloudflare - WAF protects WordPress applications from two high-severity vulnerabilities
Original: https://wearecoded.com/en/articles/cloudflare-waf-wordpress-dve-dupki.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news