Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
mitre·CWE-601·Published 2018-04-14