Description
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
Remediation
References
Related Vulnerabilities
GlassFish CVE-2017-3247 Vulnerability (CVE-2017-3247)
Python Credentials Management Errors Vulnerability (CVE-2019-10160)
WordPress Plugin Simple Download Monitor Multiple Vulnerabilities (3.2.8)
MySQL CVE-2021-2307 Vulnerability (CVE-2021-2307)
Plone CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-5493)