CVE-2018-10101: Debian Linux
Medium severity, CVSS 6.1. EPSS: 2.6% chance of exploitation in the next 30 days.
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- WordPress WordPress: before 4.9.5 (fixed in 4.9.5)
Published 2018-04-16. Last modified 2026-06-17.