Props to Evan Ricafort for finding an issue where stored XSS (cross-site scripting)
could be added via the Customizer.
rops to J.D. Grimes who found and disclosed a method of viewing unauthenticated posts.
Props to Weston Ruter for finding a way to create a stored XSS to inject Javascript
into style tags.
rops to David Newman for highlighting a method to poison the cache of JSON GET requests
via the Vary: Origin header.
Props to Eugene Kolodenker who found a server-side request forgery in the way that URLs
are validated.
Props to Ben Bidner of the WordPress Security Team who discovered issues related to
referrer validation in the admin.