Security Advisory
CVE-2018-10101
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.