CVE-2018-20148: Debian Linux
Critical severity, CVSS 9.8. EPSS: 26.8% chance of exploitation in the next 30 days.
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- WordPress WordPress: before 4.9.9 (fixed in 4.9.9); from 5.0, before 5.0.1 (fixed in 5.0.1)
Published 2018-12-14. Last modified 2026-06-17.