Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
https://wpvulndb.com/vulnerabilities/8474
https://core.trac.wordpress.org/query?status=closed&milestone=4.5
http://www.securityfocus.com/bid/92390