Description
ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class.
Remediation
References
Related Vulnerabilities
WordPress Plugin youForms for WordPress-Creating Forms for CopeCart Cross-Site Scripting (1.0.5)
WordPress Other Vulnerability (CVE-2021-44223)
WordPress Plugin fMoblog 'id' Parameter SQL Injection (2.1)
WordPress Plugin Efence Multiple Cross-Site Scripting Vulnerabilities (1.3.2)
WordPress Plugin Joy Of Text Lite-SMS messaging for WordPress SQL Injection (2.3.0)