WordPress doesn't to LTS. WordPress usually backports security fixes to older branches (like the 6.x branches) but going all the way back to 4.x isn't something they'll do for every fix. Who knows how many bugs lie in wait for older versions that are out of support.
If you run WordPress, you should be aware of this already. Either upgrade to the latest versions, constantly and quickly, or have extremely restrictive WAFs up and ready. Especially if you have any plugins installed (as those are usually where the WordPress exploits are coming from).
I'd recommend everyone unhappy only finding out about WordPress' long-standing support policy to ask their money back.