WordPress 5.9.3
WordPress 5.9.3 has 35 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2025; all 35 are fixed as of August 2026. Their average CVSS score is 5.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 4 high. 2022 was the busiest year with 15 disclosures.
The most common weakness is Cross-Site Scripting, behind 15 of the records (43%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Acceptance Of Extraneous Untrusted Data With Trusted Data.
Every one of the 35 issues recorded for WordPress 5.9.3 has a vendor fix available, so running the current release closes all known holes.
24 independent researchers contributed these findings, most of them (4) reported by Alex Concha.
WordPress Core < 6.0.3 - SQL Injection via WP_Date_Query
Read the full analysisVulnerability Records
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C