WAF rules now block CVE-2026-60137 (SQL injection) and CVE-2026-63030 (unauthenticated RCE in REST API batch endpoint) across free and paid plans, but patching remains mandatory.
Summary
WordPress sites get immediate WAF protection while you patch, but RCE exploits the REST API batch endpoint when persistent object cache is absent—a common configuration gap. Verify your cache setup and patch status now.
Why it matters
WordPress sites get immediate WAF protection while you patch, but RCE exploits the REST API batch endpoint when persistent object cache is absent—a common configuration gap. Verify your cache setup and patch status now.
Implementation verdict
Replaces manual exploit monitoring on Cloudflare-proxied traffic. Requires: enable Managed Rules (Pro+) or verify Free Ruleset activation, review ruleset overrides that log instead of block, confirm WordPress patched to 7.0.2, 6.9.5, 6.8.6, or 7.1 Beta 2. Ready now but insufficient alone—patch immediately.
Sources
Dev Signal
Get briefs like this in your inbox — free, every weekday.
100+ sources compressed into one 4-minute read. Ranked, cited, implementation-ready.