LIVE · cybersecurity feed
Live wire

waf

CVE-2026-60137critical

Cloudflare WAF Shields WordPress From Critical RCE and SQL Injection Flaws

Cloudflare has released new Web Application Firewall (WAF) rules to protect WordPress sites from two severe vulnerabilities. These flaws include an unauthenticated remote code execution (RCE) bug in the REST API and a related SQL injection vulnerability, affecting specific versions of WordPress. While Cloudflare's WAF provides immediate protection, users are strongly advised to update their WordPress installations to the patched versions released by the WordPress security team.