A type of attack called cross-site request forgery (CSRF) was discovered in versions of WordPress before 4.7.1. This type of attack allowed remote attackers to gain control of another person’s account without their knowledge. This was done by using a file that was uploaded with a Flash program.