CVE-2018-20149: Debian Linux

Medium severity, CVSS 5.4. EPSS: 2.9% chance of exploitation in the next 30 days.

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • WordPress WordPress: before 4.9.9 (fixed in 4.9.9); from 5.0, before 5.0.1 (fixed in 5.0.1)

Published 2018-12-14. Last modified 2026-06-17.