Description
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted call.
Remediation
References
Related Vulnerabilities
WordPress Plugin My Link Order Cross-Site Scripting (4.3)
WordPress Plugin Zendesk Chat Cross-Site Scripting (1.2.5)
WordPress Plugin WP Editor.md Cross-Site Scripting (10.0.1)
WordPress Plugin Redirection Multiple Cross-Site Scripting Vulnerabilities (2.2.11)
WordPress Plugin Simple PDF Viewer Cross-Site Scripting (1.9)