Switch language한국어
Back to the list

Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities

TL;DR AI

Key summary

2 min read
  1. Cloudflare has rolled out WAF protections for two severe WordPress vulnerabilities.

  2. The issues include a high-severity SQL injection flaw and an unauthenticated remote code execution bug tied to the REST API.

  3. The rules were pushed to all customers using Cloudflare proxied traffic, including free-plan users.

  4. WordPress has released fixes in version 7.0.2 and backports for affected branches, while forcing automatic updates on vulnerable sites.

  5. Cloudflare said the WAF helps reduce exposure, but administrators still need to install the WordPress patches.

Read the original