WordPress · Wordpress · CVE-2018-10100
Name of the Vulnerable Software and Affected Versions:
WordPress versions prior to 4.9.5
Description:
The issue concerns the login page's redirection URL, which was not properly validated or sanitized when forced to use HTTPS.
Recommendations:
For versions prior to 4.9.5, update to version 4.9.5 or later to resolve the issue.