WordPress 5.9.5

WordPress 5.9.5 has 20 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2025; all 20 are fixed as of August 2026. Their average CVSS score is 5.6, and the most serious one scores 6.6 out of 10. 2023 was the busiest year with 12 disclosures.

The most common weakness is Cross-Site Scripting, behind 8 of the records (40%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Acceptance Of Extraneous Untrusted Data With Trusted Data.

Every one of the 20 issues recorded for WordPress 5.9.5 has a vendor fix available, so running the current release closes all known holes.

15 independent researchers contributed these findings, most of them (3) reported by Rafie Muhammad.

01234567891020.06.2012Today20.06.20123.7WordPress Core - Informational < 6.8 - Weak Hashing Algorithm CVSS 3.7 · 20.06.201204.08.20186.6WordPress Core < 6.4.3 - Authenticated(Administrator+) PHP File Upload CVSS 6.6 · 04.08.201816.05.20234.3WordPress Core < 6.2.1 - Cross-Site Request Forgery CVSS 4.3 · 16.05.20236.4WordPress Core < 6.2.1 - Insufficient Sanitization of Block Attributes CVSS 6.4 · 16.05.20236.4WordPress Core < 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Embed Discovery CVSS 6.4 · 16.05.20235.4WordPress Core < 6.2.1 - Directory Traversal CVSS 5.4 · 16.05.202319.05.20236.5WordPress Core < 6.2.1 - Shortcode Execution in User Generated Content CVSS 6.5 · 19.05.20236.5WordPress Core < 6.2.2 - Shortcode Execution in User Generated Content CVSS 6.5 · 19.05.202312.10.20236.1WordPress Core 5.6 - 6.3.1 - Reflected Cross-Site Scripting via Application Password Requests CVSS 6.1 · 12.10.20236.4WordPress Core 5.9-6.3.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Navigation Attributes CVSS 6.4 · 12.10.20234.3WordPress Core <= 6.3.1 - Authenticated(Contributor+) Sensitive Information Exposure via Comments on Protected Posts CVSS 4.3 · 12.10.20235.3WordPress Core 4.7.0 - 6.3.1 - Sensitive Information Exposure via User Search REST Endpoint CVSS 5.3 · 12.10.20235.3WordPress Core 4.7.0-6.3.1 - Denial of Service via Cache Poisoning CVSS 5.3 · 12.10.20235.4WordPress Core < 6.3.2 – Authenticated (Subscriber+) Arbitrary Shortcode Execution via parse-media-shortcode CVSS 5.4 · 12.10.202304.04.20245.3WordPress Core <= 6.4.3 - Sensitive Information Exposure via redirect_guess_404_permalink CVSS 5.3 · 04.04.202424.06.20246.4WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML API CVSS 6.4 · 24.06.20246.4WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Template Part Block CVSS 6.4 · 24.06.20244.3WordPress Core < 6.5.5 - Authenticated (Contributor+) Directory Traversal CVSS 4.3 · 24.06.202422.09.20254.3WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure CVSS 4.3 · 22.09.20256.4WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting CVSS 6.4 · 22.09.2025

Strategic Overview

Avg CVSSMedium
5.6/ 10
Patch Coverage100%
Open

0

Fixed

20

Get automatic notifications for all WordPress 5.9.5 vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.6CVE-2018-14028

WordPress Core < 6.4.3 - Authenticated(Administrator+) PHP File Upload

Read the full analysis

Vulnerability Records

20 records
2025-09-22 00:00CVE-2025-58246
4.3
Medium
Abu Hurayra (HurayraIIT)Yes
2025-09-22 00:00CVE-2025-58674
6.4
Medium
SavPhill (Savphill)Yes
2024-06-24 00:00CVE-2024-6307
6.4
Medium
Alex ConchaYes
2024-06-24 00:00CVE-2024-31111
6.4
Medium
Rafie MuhammadYes
2024-06-24 00:00CVE-2024-32111
4.3
Medium
apple502jYes
2024-04-04 00:00CVE-2023-5692
5.3
Medium
Francesco CarlucciYes
2023-10-12 00:00N/A
6.1
Medium
mascara7784Yes
2023-10-12 00:00CVE-2023-38000
6.4
Medium
Rafie MuhammadYes
2023-10-12 00:00CVE-2023-39999
4.3
Medium
Rafie MuhammadYes
2023-10-12 00:00CVE-2023-5561
5.3
Medium
Marc-Alexandre MontpasYes
Showing 1–10 of 20 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C