WordPress before 5.2.3 allows XSS in post previews by authenticated users. Reference: https://wpvulndb.com/vulnerabilities/9862
Created wordpress tracking bugs for this issue: Affects: epel-6 [bug 1776451] Affects: epel-7 [bug 1776452]