Description
ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive information by using a (1) string or (2) array data type in place of a numeric data type, as demonstrated by an imagecrop function call with a string for the x dimension value, a different vulnerability than CVE-2013-7226.
Remediation
References
Related Vulnerabilities
WordPress Plugin Top 10-Popular posts for WordPress Cross-Site Scripting (2.3.0)
MySQL CVE-2016-5584 Vulnerability (CVE-2016-5584)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Directory Traversal (1.3.42)
WordPress Plugin Easy Forms for MailChimp Cross-Site Scripting (6.1.2)