WordPress versions before 3.9.2 had a security flaw that made it easier for attackers to get around the protection that was in place to prevent unwanted access. This was because it didn’t always separate parts of the code that was used to make sure that only authorized users could access certain features. This made it easier for attackers to guess the code and gain access.