WordPress 6.0.2
WordPress 6.0.2 has 33 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2025; all 33 are fixed as of August 2026. Their average CVSS score is 5.9, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 4 high. 2023 was the busiest year with 12 disclosures.
The most common weakness is Cross-Site Scripting, behind 14 of the records (42%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Acceptance Of Extraneous Untrusted Data With Trusted Data.
Every one of the 33 issues recorded for WordPress 6.0.2 has a vendor fix available, so running the current release closes all known holes.
22 independent researchers contributed these findings, most of them (4) reported by Alex Concha.
WordPress Core < 6.0.3 - SQL Injection via WP_Date_Query
Read the full analysisVulnerability Records
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C