WordPress 5.9.1

WordPress 5.9.1 has 38 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2025; all 38 are fixed as of August 2026. Their average CVSS score is 5.9, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 5 high. 2022 was the busiest year with 18 disclosures.

The most common weakness is Cross-Site Scripting, behind 16 of the records (42%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Acceptance Of Extraneous Untrusted Data With Trusted Data.

Every one of the 38 issues recorded for WordPress 5.9.1 has a vendor fix available, so running the current release closes all known holes.

26 independent researchers contributed these findings, most of them (4) reported by Alex Concha.

01234567891020.06.2012Today20.06.20123.7WordPress Core - Informational < 6.8 - Weak Hashing Algorithm CVSS 3.7 · 20.06.201204.08.20186.6WordPress Core < 6.4.3 - Authenticated(Administrator+) PHP File Upload CVSS 6.6 · 04.08.201811.03.20225.4WordPress Core < 5.9.2 & Gutenberg < 12.7.2 - Prototype Pollution via Block Editor CVSS 5.4 · 11.03.20228.8WordPress Core < 5.9.1 - jQuery Prototype Pollution CVSS 8.8 · 11.03.20226.4WordPress Core 5.9 - 5.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 11.03.202230.08.20224.4WordPress Core < 6.0.2 - Stored Cross-Site Scripting via Plugin Deactivation and Deletion Errors CVSS 4.4 · 30.08.20228.0WordPress Core < 6.0.2 - Authenticated SQL Injection CVSS 8.0 · 30.08.20224.9WordPress Core < 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function CVSS 4.9 · 30.08.202218.10.20228.8WordPress Core < 6.0.3 - Cross-Site Request Forgery via wp-trackback.php CVSS 8.8 · 18.10.20227.2WordPress Core < 6.0.3 - Stored Cross-Site Scripting via wp-mail.php CVSS 7.2 · 18.10.20225.3WordPress Core < 6.0.3 - Information Disclosure (Email Address) CVSS 5.3 · 18.10.20223.7WordPress Core < 6.0.3 - Information Disclosure (Multi-Part Email Leak) CVSS 3.7 · 18.10.20225.4WordPress Core < 6.0.3 - Open Redirect CVSS 5.4 · 18.10.20223.7WordPress Core < 6.0.3 - Shared User Instance Weakness CVSS 3.7 · 18.10.20225.5WordPress Core < 6.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting via Customizer CVSS 5.5 · 18.10.20226.4WordPress Core < 6.0.3 & Gutenberg < 14.3.1 - Authenticated Cross-Site Scripting in Various Blocks CVSS 6.4 · 18.10.20224.3WordPress Core < 6.0.3 - Authenticated Information Disclosure via REST-API CVSS 4.3 · 18.10.20228.8WordPress Core < 6.0.3 - Reflected Cross-Site Scripting via SQL Injection CVSS 8.8 · 18.10.20229.8WordPress Core < 6.0.3 - SQL Injection via WP_Date_Query CVSS 9.8 · 18.10.20225.5WordPress Core < 6.0.3 - Authenticated (Editor+) Stored Cross-Site Scripting via Comments CVSS 5.5 · 18.10.202216.05.20234.3WordPress Core < 6.2.1 - Cross-Site Request Forgery CVSS 4.3 · 16.05.20236.4WordPress Core < 6.2.1 - Insufficient Sanitization of Block Attributes CVSS 6.4 · 16.05.20236.4WordPress Core < 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Embed Discovery CVSS 6.4 · 16.05.20235.4WordPress Core < 6.2.1 - Directory Traversal CVSS 5.4 · 16.05.202319.05.20236.5WordPress Core < 6.2.1 - Shortcode Execution in User Generated Content CVSS 6.5 · 19.05.20236.5WordPress Core < 6.2.2 - Shortcode Execution in User Generated Content CVSS 6.5 · 19.05.202312.10.20236.1WordPress Core 5.6 - 6.3.1 - Reflected Cross-Site Scripting via Application Password Requests CVSS 6.1 · 12.10.20236.4WordPress Core 5.9-6.3.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Navigation Attributes CVSS 6.4 · 12.10.20234.3WordPress Core <= 6.3.1 - Authenticated(Contributor+) Sensitive Information Exposure via Comments on Protected Posts CVSS 4.3 · 12.10.20235.3WordPress Core 4.7.0 - 6.3.1 - Sensitive Information Exposure via User Search REST Endpoint CVSS 5.3 · 12.10.20235.3WordPress Core 4.7.0-6.3.1 - Denial of Service via Cache Poisoning CVSS 5.3 · 12.10.20235.4WordPress Core < 6.3.2 – Authenticated (Subscriber+) Arbitrary Shortcode Execution via parse-media-shortcode CVSS 5.4 · 12.10.202304.04.20245.3WordPress Core <= 6.4.3 - Sensitive Information Exposure via redirect_guess_404_permalink CVSS 5.3 · 04.04.202424.06.20246.4WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML API CVSS 6.4 · 24.06.20246.4WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Template Part Block CVSS 6.4 · 24.06.20244.3WordPress Core < 6.5.5 - Authenticated (Contributor+) Directory Traversal CVSS 4.3 · 24.06.202422.09.20254.3WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure CVSS 4.3 · 22.09.20256.4WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting CVSS 6.4 · 22.09.2025

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage100%
Open

0

Fixed

38

Get automatic notifications for all WordPress 5.9.1 vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8

WordPress Core < 6.0.3 - SQL Injection via WP_Date_Query

Read the full analysis

Vulnerability Records

38 records
2025-09-22 00:00CVE-2025-58246
4.3
Medium
Abu Hurayra (HurayraIIT)Yes
2025-09-22 00:00CVE-2025-58674
6.4
Medium
SavPhill (Savphill)Yes
2024-06-24 00:00CVE-2024-6307
6.4
Medium
Alex ConchaYes
2024-06-24 00:00CVE-2024-31111
6.4
Medium
Rafie MuhammadYes
2024-06-24 00:00CVE-2024-32111
4.3
Medium
apple502jYes
2024-04-04 00:00CVE-2023-5692
5.3
Medium
Francesco CarlucciYes
2023-10-12 00:00N/A
6.1
Medium
mascara7784Yes
2023-10-12 00:00CVE-2023-38000
6.4
Medium
Rafie MuhammadYes
2023-10-12 00:00CVE-2023-39999
4.3
Medium
Rafie MuhammadYes
2023-10-12 00:00CVE-2023-5561
5.3
Medium
Marc-Alexandre MontpasYes
Showing 1–10 of 38 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C