WordPress 5.9.6
WordPress 5.9.6 has 15 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2025; all 15 are fixed as of August 2026. Their average CVSS score is 5.5, and the most serious one scores 6.6 out of 10. 2023 was the busiest year with 7 disclosures.
The most common weakness is Cross-Site Scripting, behind 6 of the records (40%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Acceptance Of Extraneous Untrusted Data With Trusted Data.
Every one of the 15 issues recorded for WordPress 5.9.6 has a vendor fix available, so running the current release closes all known holes.
12 independent researchers contributed these findings, most of them (3) reported by Rafie Muhammad.
CVE-2018-14028WordPress Core < 6.4.3 - Authenticated(Administrator+) PHP File Upload
Read the full analysisVulnerability Records
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C