WordPress versions before 5.1.1 have a security flaw that could allow someone who is not authenticated to take control of the website and make changes to the code. This is due to two problems – the website is not properly protecting against malicious code that could be added to comments