Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities

TL;DR AI
2 min readKey summary
Cloudflare has rolled out WAF protections for two severe WordPress vulnerabilities.
The issues include a high-severity SQL injection flaw and an unauthenticated remote code execution bug tied to the REST API.
The rules were pushed to all customers using Cloudflare proxied traffic, including free-plan users.
WordPress has released fixes in version 7.0.2 and backports for affected branches, while forcing automatic updates on vulnerable sites.
Cloudflare said the WAF helps reduce exposure, but administrators still need to install the WordPress patches.
