WordPress 5.9.4

WordPress 5.9.4 has 32 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2025; all 32 are fixed as of August 2026. Their average CVSS score is 5.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 3 high. 2023 was the busiest year with 12 disclosures.

The most common weakness is Cross-Site Scripting, behind 13 of the records (41%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Acceptance Of Extraneous Untrusted Data With Trusted Data.

Every one of the 32 issues recorded for WordPress 5.9.4 has a vendor fix available, so running the current release closes all known holes.

22 independent researchers contributed these findings, most of them (4) reported by Alex Concha.

01234567891020.06.2012Today20.06.20123.7WordPress Core - Informational < 6.8 - Weak Hashing Algorithm CVSS 3.7 · 20.06.201204.08.20186.6WordPress Core < 6.4.3 - Authenticated(Administrator+) PHP File Upload CVSS 6.6 · 04.08.201818.10.20228.8WordPress Core < 6.0.3 - Cross-Site Request Forgery via wp-trackback.php CVSS 8.8 · 18.10.20227.2WordPress Core < 6.0.3 - Stored Cross-Site Scripting via wp-mail.php CVSS 7.2 · 18.10.20225.3WordPress Core < 6.0.3 - Information Disclosure (Email Address) CVSS 5.3 · 18.10.20223.7WordPress Core < 6.0.3 - Information Disclosure (Multi-Part Email Leak) CVSS 3.7 · 18.10.20225.4WordPress Core < 6.0.3 - Open Redirect CVSS 5.4 · 18.10.20223.7WordPress Core < 6.0.3 - Shared User Instance Weakness CVSS 3.7 · 18.10.20225.5WordPress Core < 6.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting via Customizer CVSS 5.5 · 18.10.20226.4WordPress Core < 6.0.3 & Gutenberg < 14.3.1 - Authenticated Cross-Site Scripting in Various Blocks CVSS 6.4 · 18.10.20224.3WordPress Core < 6.0.3 - Authenticated Information Disclosure via REST-API CVSS 4.3 · 18.10.20228.8WordPress Core < 6.0.3 - Reflected Cross-Site Scripting via SQL Injection CVSS 8.8 · 18.10.20229.8WordPress Core < 6.0.3 - SQL Injection via WP_Date_Query CVSS 9.8 · 18.10.20225.5WordPress Core < 6.0.3 - Authenticated (Editor+) Stored Cross-Site Scripting via Comments CVSS 5.5 · 18.10.202216.05.20234.3WordPress Core < 6.2.1 - Cross-Site Request Forgery CVSS 4.3 · 16.05.20236.4WordPress Core < 6.2.1 - Insufficient Sanitization of Block Attributes CVSS 6.4 · 16.05.20236.4WordPress Core < 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Embed Discovery CVSS 6.4 · 16.05.20235.4WordPress Core < 6.2.1 - Directory Traversal CVSS 5.4 · 16.05.202319.05.20236.5WordPress Core < 6.2.1 - Shortcode Execution in User Generated Content CVSS 6.5 · 19.05.20236.5WordPress Core < 6.2.2 - Shortcode Execution in User Generated Content CVSS 6.5 · 19.05.202312.10.20236.1WordPress Core 5.6 - 6.3.1 - Reflected Cross-Site Scripting via Application Password Requests CVSS 6.1 · 12.10.20236.4WordPress Core 5.9-6.3.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Navigation Attributes CVSS 6.4 · 12.10.20234.3WordPress Core <= 6.3.1 - Authenticated(Contributor+) Sensitive Information Exposure via Comments on Protected Posts CVSS 4.3 · 12.10.20235.3WordPress Core 4.7.0 - 6.3.1 - Sensitive Information Exposure via User Search REST Endpoint CVSS 5.3 · 12.10.20235.3WordPress Core 4.7.0-6.3.1 - Denial of Service via Cache Poisoning CVSS 5.3 · 12.10.20235.4WordPress Core < 6.3.2 – Authenticated (Subscriber+) Arbitrary Shortcode Execution via parse-media-shortcode CVSS 5.4 · 12.10.202304.04.20245.3WordPress Core <= 6.4.3 - Sensitive Information Exposure via redirect_guess_404_permalink CVSS 5.3 · 04.04.202424.06.20246.4WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML API CVSS 6.4 · 24.06.20246.4WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Template Part Block CVSS 6.4 · 24.06.20244.3WordPress Core < 6.5.5 - Authenticated (Contributor+) Directory Traversal CVSS 4.3 · 24.06.202422.09.20254.3WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure CVSS 4.3 · 22.09.20256.4WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting CVSS 6.4 · 22.09.2025

Strategic Overview

Avg CVSSMedium
5.8/ 10
Patch Coverage100%
Open

0

Fixed

32

Get automatic notifications for all WordPress 5.9.4 vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8

WordPress Core < 6.0.3 - SQL Injection via WP_Date_Query

Read the full analysis

Vulnerability Records

32 records
2025-09-22 00:00CVE-2025-58246
4.3
Medium
Abu Hurayra (HurayraIIT)Yes
2025-09-22 00:00CVE-2025-58674
6.4
Medium
SavPhill (Savphill)Yes
2024-06-24 00:00CVE-2024-6307
6.4
Medium
Alex ConchaYes
2024-06-24 00:00CVE-2024-31111
6.4
Medium
Rafie MuhammadYes
2024-06-24 00:00CVE-2024-32111
4.3
Medium
apple502jYes
2024-04-04 00:00CVE-2023-5692
5.3
Medium
Francesco CarlucciYes
2023-10-12 00:00N/A
6.1
Medium
mascara7784Yes
2023-10-12 00:00CVE-2023-38000
6.4
Medium
Rafie MuhammadYes
2023-10-12 00:00CVE-2023-39999
4.3
Medium
Rafie MuhammadYes
2023-10-12 00:00CVE-2023-5561
5.3
Medium
Marc-Alexandre MontpasYes
Showing 1–10 of 32 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C