WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).
https://wpvulndb.com/vulnerabilities/9006
https://wordpress.org/news/2018/01/wordpress-4-9-2-security-and-maintenance-release/
https://github.com/WordPress/WordPress/commit/3fe9cb61ee71fcfadb5e002399296fcc1198d850