WordPress 6.0.4
WordPress 6.0.4 has 16 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2025; all 16 are fixed as of August 2026. Their average CVSS score is 5.6, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high. 2023 was the busiest year with 7 disclosures.
The most common weakness is Cross-Site Scripting, behind 7 of the records (44%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Acceptance Of Extraneous Untrusted Data With Trusted Data.
Every one of the 16 issues recorded for WordPress 6.0.4 has a vendor fix available, so running the current release closes all known holes.
13 independent researchers contributed these findings, most of them (3) reported by Rafie Muhammad.
CVE-2024-4439WordPress Core < 6.5.2 - Unauthenticated & Authenticated (Contributor+) Stored Cross-Site Scripting via Avatar Block
Read the full analysisVulnerability Records
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C