WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
https://www.debian.org/security/2020/dsa-4677
https://www.debian.org/security/2020/dsa-4599
https://wpvulndb.com/vulnerabilities/9910
https://wordpress.org/news/2019/10/wordpress-5-2-4-security-release/