End of life / WordPress / 6.9
WordPress 6.9 end of life
WordPress 6.9 has no published end of life date. 4 known CVEs reach this release, the most severe rated CRITICAL.
The detail
- Released
- 2 December 2025
- End of life
- not published
- Countdown
- no published end of life date
- Status
- No published date
- Support phase
- Security supported
- Long term support
- No
- Newest build on this release
- 6.9.7
- Newest release overall
- 7.1.0
CVEs that reach 6.9
| Advisory | Severity | CVSS | Published | Fixed in |
|---|---|---|---|---|
| CVE-2026-63030 REST API batch-route confusion and SQL injection issue leading to Remote Code Execution | CRITICAL | - | 17 July 2026 | 6.9.5 |
| CVE-2026-64638 Pre-auth reflected XSS on login screen with potential to lead to PHP code execution | HIGH | 8.9 | 6 August 2026 | 6.9.6 |
| CVE-2026-65640 Remote code execution vulnerability via malicious file upload by an Author level user or higher | HIGH | 8.8 | 12 August 2026 | 6.9.7 |
| CVE-2026-60137 Facilitated SQL injection vulnerability in the `author__not_in` parameter of `WP_Query` | MEDIUM | - | 17 July 2026 | 6.9.5 |
A further 2 advisories publish no version range, so whether they reach 6.9 cannot be determined from the advisory alone.
Where to move next
The newest tracked release is 7.1.0. If moving release is not an option yet, 6.9.7 is the newest build on the 6.9 line and needs no migration.
Other WordPress releases
Vendor sources last checked 6 September 2026, and checked daily. This data last changed on 6 September 2026.
You just looked this up by hand, for one version
StackDrift scans your machines, works out every version you actually run, and mails you before the next support window closes or a CVE lands on a build you have deployed. It covers the runtimes, operating systems and kernels underneath your code, not just your packages.