WordPress versions before 4.1.2 had security vulnerabilities which allowed attackers to insert malicious code into a website. This code could be written in a comment and was triggered by either a four-byte Unicode character or an invalid character. This allowed the attacker to run scripts on the website