Cloudflare has deployed new Web Application Firewall (WAF) protections for two critical vulnerabilities affecting WordPress.
What happened
Cloudflare has deployed new Web Application Firewall (WAF) protections for two critical vulnerabilities affecting WordPress. The protections address an Unauthenticated Remote Code Execution (RCE) vulnerability in WordPress's REST API and a related SQL Injection vulnerability. The floor is firmer here because the story is anchored by an official source, not only by second-hand reaction. In security, the real value is whether the team becomes measurably safer, not whether another settings screen has been added.
Practical impact for readers
The WordPress security team disclosed the vulnerabilities to Cloudflare before public release so that we could prepare protections for customers. Cloudflare has deployed the new rules to protect all customers, including those on free and paid plans, as long as their application traffic is proxied through the Cloudflare WAF. The rules were deployed at 17:03 UTC on July 17 2026.
Details worth verifying
WAF protections reduce exposure while customers update, but they are not a substitute for patching. WordPress has released fixes in version 7. 0. 2, with backports to affected earlier branches: 6. 9. 5, 6. 8. 6, and 7. 1 Beta 2 ( see release details ). Versions earlier than 6. 8 are not affected. WordPress is treating this as its highest-severity, highest-priority class of issue and is forcing automatic updates to affected sites, so most sites will be updated automatically. We still recommend confirming that you are on a patched release or the backports for your branch and follow the guidance in the official WordPress security release announcement .
Who should act or wait
Cloudflare customers running WordPress sites on Pro, Business, or Enterprise plans should ensure that Cloudflare Managed Rules are enabled. Customers can follow the steps in our WAF Managed Rules documentation . Customers on free plans are automatically protected through the Free Ruleset. In security, the next follow-up is patch speed, real adoption, and whether teams actually keep the safer behavior in place. That is why the useful reading move is not to stop at the headline, but to compare the promise, the workflow change, and the likely cost before deciding anything.
What is still unclear
The new rules are deployed with the default Managed Ruleset action of Block. Customers running WordPress sites should review any ruleset-level overrides, including those that change all rules from Block to Log, and ensure the new rules use the recommended action while they update WordPress. Cloudflare customers should also monitor Security Events for requests matching either rule.
Latest comments
0No comments yet. You can start the conversation.