ZeroHour

CVE-2018-10100

CVSS 3.0
6.1 medium
EPSS
3%p85
Published
()
Modified
Description

Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.

Vendors
wordpressdebian
Products
wordpress, debian linux
Ecosystems
WordPress
Weakness
CWE-601
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.