A security flaw in versions of WordPress before 4.2.4 allowed attackers to insert malicious code into a website using a feature called refreshAdvancedAccessibilityOfItem in wp-admin/js/nav-menu.js. This code could be used to harm the website or its viewers.