WordPress versions prior to 4.6.1 had a security vulnerability which could allow malicious actors to inject malicious code into a website. An attacker could achieve this by convincing an administrator on the site to upload an image file with a special