WordPress Core is susceptible to a security issue called Stored Cross-Site Scripting. This can happen in different versions up to 6.5.5 because the input and output of URLs are not properly checked for harmful code. This means that people who are logged in and have a certain level of access can add harmful code to a page, which will then execute when someone else views that page.