WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
https://www.debian.org/security/2020/dsa-4677
https://www.debian.org/security/2020/dsa-4599
https://wpvulndb.com/vulnerabilities/9908
https://wordpress.org/news/2019/10/wordpress-5-2-4-security-release/