Description
In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.
Remediation
References
Related Vulnerabilities
WordPress Plugin Accessibility Suite by Online ADA SQL Injection (2.0.10)
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-32028)
WordPress Plugin WP-RecentComments Information Disclosure (2.2.7)
WordPress Plugin WP Learn Manager Cross-Site Scripting (1.1.2)