Timthumb.php security flaw makes hacking your WordPress site simple
by Fergus Kelly. Average Reading Time: less than a minute.
Tags: Content management systems, PHP, Plugins, Security, WordPress
A vulnerability has been found in the very popular image resizer timthumb.php which hackers to easily compromise your site. Timthumb is particularly popular in WordPress themes and plugins. This exploit is particularly dangerous and should be fixed urgently.
The author of timthumb has updated the library to patch the vulnerability and Mark Maunder who was first to discover the exploit has posted in detail on how to fix the problem in older versions.
Other security sites are recommending the deletion of timthumb.php or thumb.php entirely if your site will work without it.
