WordPress 5.9.1
WordPress 5.9.1 has 38 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2025; all 38 are fixed as of August 2026. Their average CVSS score is 5.9, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 5 high. 2022 was the busiest year with 18 disclosures.
The most common weakness is Cross-Site Scripting, behind 16 of the records (42%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Acceptance Of Extraneous Untrusted Data With Trusted Data.
Every one of the 38 issues recorded for WordPress 5.9.1 has a vendor fix available, so running the current release closes all known holes.
26 independent researchers contributed these findings, most of them (4) reported by Alex Concha.
WordPress Core < 6.0.3 - SQL Injection via WP_Date_Query
Read the full analysisVulnerability Records
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C