The WordPress core has two vulnerabilities, and the more severe one lets an unauthenticated attacker run their own code on the server. Cloudflare rolled out protective rules for all its customers on July 17, while the patches roll out. For anyone running a shop or site on WordPress, this is one of those things that won't wait until Monday.
- Two vulnerabilities in the WordPress core: SQL injection (high) and unauthenticated remote code execution (critical).
- Cloudflare rolled out WAF rules for all plans on July 17, 2026 (17:03 UTC); the protection buys time, it doesn't replace the patch.
- Patched versions: 7.0.2, 6.9.5, 6.8.6. Advice: check your version and update now, especially if it's a WooCommerce shop.
I checked ours before sitting down to write this. We run client shops on exactly this stack - WordPress behind Cloudflare - and this week two vulnerabilities dropped in the core at once.
That's why I read this as today's task, not as a headline. Cloudflare reacted fast and clean - a shield for everyone, hours after the holes went public, even on the free plans. That's the right move.
Except the shield is a bandage, not a cure. It stops the known shape of the attack at the door; the patch closes the hole itself. It matters because the critical one of the two needs neither a password nor an account - it works down a list of addresses, not a specific target. And the uncomfortable truth about WordPress is that a huge share of sites update late or never.
We're pulling up the list of client WordPress and WooCommerce sites and checking the version. 6.8 and up - update to the patched one. Being behind Cloudflare makes us calmer, but calm isn't a patch. I know what someone will say. It works, why touch it. Those exact sites are on the automated attacker's list. You update today. Not on Monday.