WordPress version 4.0.1 was released to fix a serious issue that occurred in all versions of the CMS (content management system) from version 4.0 and before, which in fact constitutes 85.5% of WordPress installations.
This system vulnerability had gone unnoticed for about four years, having existed since version 3.0 of the CMS, released in 2010. Discovered by Jouko Pynnonen of Finnish IT company Klikki Oy, this vulnerability allows the execution of arbitrary JavaScript in user comment boxes.
The commands are located within the page script and run with administrator privileges when the victim user tries to view a comment on the page. One way to do this is to hide the malicious Javascript between various URLs within the comment. The text is passed to the system’s review queue and once the administrator sees it, the dangerous commands will be executed.
With this location, the script cannot be detected by search engines or other users. In an explanation provided by IT Klikki Oy, it informs that all operations are performed in the background without being seen. The attacker could execute commands to change the current user's password, create a new admin account, and much more to damage the page.
Even more worrying, however, is the ability to add malicious PHP to the server via the editor, and immediately execute it with an Ajax request. This could allow the attacker to gain access to the server's operating system.
All WordPress page administrators should install the latest update so that they don't have any problems with the security of their pages.

