Description
In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.
Remediation
References
Related Vulnerabilities
WordPress Plugin Import/Export Customizer Settings Cross-Site Request Forgery (1.0.3)
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-34467)
WordPress Plugin Related Posts Unspecified Vulnerability (5.12.69)
WordPress Plugin Coming Soon Page & Maintenance Mode Unspecified Vulnerability (1.8.2)