A WAF is a filter in front of the site - it watches incoming requests and stops the harmful ones before they reach the application itself. It doesn't fix the hole. It guards it while you patch it.
The distinction that confuses people: a WAF doesn't fix the bug in the code. The hole stays exactly where it was. The WAF just stands in front of it and won't let the attack through - like a guard in front of a broken lock. That's why providers like Cloudflare push out "managed rules" the moment a new vulnerability appears. They buy everyone time to update.
So it should never replace the patch. The shield only guards against the known form of the attack, and only while you stand behind it. Pull the site out from behind the WAF-based shield, or let attackers come up with a new variant, and only one thing is left that actually closes the hole. Updating.