LiveActive security incident?Get immediate response
CVE Record

CVE-2018-10100: Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to...

Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

WordPress sites before 4.9.5 had a login-page redirect handling flaw when HTTPS was forced. A crafted login flow could send users to an unintended URL. This is more likely to support phishing or trust abuse than direct server takeover, based on the provided sources.

Executive priority

Prioritize remediation during normal security patching unless the site handles sensitive logins or is heavily targeted. The business risk is user trust and credential exposure, not proven remote server compromise from the supplied evidence.

Technical view

The issue is insufficient validation or sanitization of the login page redirection URL in WordPress before 4.9.5 when forced HTTPS is used. WordPress fixed it in the 4.9.5 security and maintenance release, with supporting upstream changesets and Debian security updates cited in the bundle.

Likely exposure

Public WordPress installations running versions before 4.9.5 are the likely exposure, especially where login is reachable and HTTPS-forced login behavior is enabled. The provided affected-product metadata is incomplete, but WordPress advisories identify the product and fixed release.

Exploitation context

The bundle does not show CISA KEV listing or confirmed active exploitation. The likely abuse pattern is redirecting users from a trusted WordPress login path to an attacker-chosen destination, which can aid phishing or credential-theft campaigns.

Researcher notes

Severity, CVSS, and CWE data are absent in the supplied CVE metadata. Treat WordPress before 4.9.5 as affected based on WordPress and Debian sources, but avoid claiming active exploitation or broader product impact without additional evidence.

Mitigation direction

  • Upgrade WordPress core to 4.9.5 or a currently supported release.
  • Apply Debian WordPress security packages where WordPress is managed by Debian packaging.
  • Review vendor guidance before relying on compensating controls.
  • Restrict administrative login exposure where business operations allow it.

Validation and detection

  • Inventory all WordPress instances and record exact core versions.
  • Confirm no production instance runs WordPress before 4.9.5.
  • Check Debian package status against DSA-4193 or DLA 1366-1 where applicable.
  • Verify login redirect behavior uses the fixed upstream validation logic.
Prepared
Confidence
medium
Sources
8

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-10100 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
8Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.