The package terser, versions from 4.8.1 to 5.0.0 and from 5.14.2 and earlier, is vulnerable to a type of cyber attack known as a Regular Expression Denial of Service (ReDoS). This type of attack can be used to make certain WordPress plugins vulnerable, as they use terser.