Security readout for executives and security teams
Plain-English summary
WordPress sites before 4.9.5 had a login-page redirect handling flaw when HTTPS was forced. A crafted login flow could send users to an unintended URL. This is more likely to support phishing or trust abuse than direct server takeover, based on the provided sources.
Executive priority
Prioritize remediation during normal security patching unless the site handles sensitive logins or is heavily targeted. The business risk is user trust and credential exposure, not proven remote server compromise from the supplied evidence.
Technical view
The issue is insufficient validation or sanitization of the login page redirection URL in WordPress before 4.9.5 when forced HTTPS is used. WordPress fixed it in the 4.9.5 security and maintenance release, with supporting upstream changesets and Debian security updates cited in the bundle.
Likely exposure
Public WordPress installations running versions before 4.9.5 are the likely exposure, especially where login is reachable and HTTPS-forced login behavior is enabled. The provided affected-product metadata is incomplete, but WordPress advisories identify the product and fixed release.
Exploitation context
The bundle does not show CISA KEV listing or confirmed active exploitation. The likely abuse pattern is redirecting users from a trusted WordPress login path to an attacker-chosen destination, which can aid phishing or credential-theft campaigns.
Researcher notes
Severity, CVSS, and CWE data are absent in the supplied CVE metadata. Treat WordPress before 4.9.5 as affected based on WordPress and Debian sources, but avoid claiming active exploitation or broader product impact without additional evidence.
Mitigation direction
- Upgrade WordPress core to 4.9.5 or a currently supported release.
- Apply Debian WordPress security packages where WordPress is managed by Debian packaging.
- Review vendor guidance before relying on compensating controls.
- Restrict administrative login exposure where business operations allow it.
Validation and detection
- Inventory all WordPress instances and record exact core versions.
- Confirm no production instance runs WordPress before 4.9.5.
- Check Debian package status against DSA-4193 or DLA 1366-1 where applicable.
- Verify login redirect behavior uses the fixed upstream validation logic.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2018-10100 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://core.trac.wordpress.org/changeset/42892CVE reference · x_refsource_CONFIRM
- https://wpvulndb.com/vulnerabilities/9054CVE reference · x_refsource_MISC
- DSA-4193CVE reference · vendor-advisory, x_refsource_DEBIAN
- https://wordpress.org/news/2018/04/wordpress-4-9-5-security-and-maintenance-release/CVE reference · x_refsource_CONFIRM
- [debian-lts-announce] 20180427 [SECURITY] [DLA 1366-1] wordpress security updateCVE reference · mailing-list, x_refsource_MLIST
- https://codex.wordpress.org/Version_4.9.5CVE reference · x_refsource_CONFIRM
- https://github.com/WordPress/WordPress/commit/14bc2c0a6fde0da04b47130707e01df850eedc7eCVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
