WordPress versions before 4.2.3 have a security vulnerability which can allow malicious users with certain privileges to inject harmful web scripts or HTML into the site. This involves the use of a special code (called a shortcode) placed inside HTML elements. This vulnerability can be found in the wp-includes/kses.php and wp-includes/shortcodes.php files.