Description
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash.
Remediation
References
Related Vulnerabilities
WordPress Plugin Essential Addons for Elementor Server-Side Request Forgery (2.9.8)
MySQL CVE-2019-2495 Vulnerability (CVE-2019-2495)
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (4.15.49)
Python Improper Input Validation Vulnerability (CVE-2023-27043)
WordPress Plugin WP Mobile Detector Arbitrary File Upload (3.5)