TimThumb vulnerability: a big number of WordPress plugins and themes are affected
Submitted by bogdan on August 4, 2011 - 7:19 am 55 Comments
// external domains that are allowed to be displayed on your website $allowedSites = array ( 'flickr.com', 'picasa.com', 'blogger.com', 'wordpress.com', 'img.youtube.com', );
- portfolio-slideshow-pro
- wp-mobile-detector
- a-wp-mobile-detector
- igit-related-posts-with-thumb-images-after-posts
- dukapress
- verve-meta-boxes
- db-toolkit
- logo-management
- wp-marketplace
- islidex
- aio-shortcodes
- category-grid-view-gallery
- WPFanPro
- igit-posts-slider-widget
- wordpress-gallery-plugin
- cms-pack
- Premium_Gallery_Manager
- dp-thumbnail
- placid-slider
- nivo-slider
- photoria
- LaunchPressTheme
- kc-related-posts-by-category
- journalcrunch
- download-manager
- wordpress-thumbnail-slider
- sugar-slider
- optimizepress
- Minimo
- Polished
- Minimal
- nebula
- TheCorporation
- TheStyle
- TuaranBlog
- striking
- MyCuisine
- AskIt
- Webly
- Aggregate
- TheSource
- reviewit
- kelontongfree
- Mentor
- SimplePress
- journalcrunch
- ecobiz
- Magnificent
- timthumb.php
- Olympia
- kingsize
- Chameleon
- DelicateNews
- videozoom-v2.0-original
- videozoom
- Envisioned
- twicet
- u-design
- genoa
- OptimizePress
- Modest
- mocell
- ephoto
- Theme
- InReview
- lightpress
- hostme
- PersonalPress
- Cadca
- arras
- tiwinoo_v3
- MyProduct
- sc4
- InterPhaseTheme
- InStyle
- LightBright
- TheProfessional
- mnfst
- freshnews
- ArtSee
- Boutique
- eStore
- Avenue
- twentyten
- XSWordPressTheme
- adcents
- Nova
- MyPhoto
- eGallery
- Striking_Premium_Corporate
- default
- Lycus
- manifesto
- cold
- DynamiX
- tarnished
- Nyke
- linepress
- DJ
- adria
- zimex
- peano
- ElegantEstate
- delight
- kelontong-free
- duotive-three
- SobhanSoft_Theme
- PureType
- yamidoo_pro
- vulcan2.1
- eGamer
- Wooden
- peritacion
- AmphionPro
- trinity
- dandelion_v2.6.3
- Juggernautgrande
- juggernaut-theme
- BlackLabel_v1.1.2
- Feather
- reviewit1
- zinepress_v1.0.1
- tribune
- photoria
- vilisya
- DailyNotes
- Basic
- minerva
- anthology_v1.4.2
- ModestTheme
- purevision
- parquet
- framed-redux
- eceramica
- InterPhase
- epsilon
- Striking
- thedawn
- peava
- Newspro
- telegraph
- averin
- telegraph_v1.1
- Memoir
- NewsPro
- CircloSquero
- vassal
- maxell
- 13Floor
- wpanniversary
- OnTheGo
- Glider
- mohannad-najjar222
- mohannad-najjar2
- arthemia
- tuufy7
- photoframe
- beach-holiday
- blacklabel
- cadabrapress
- snapwire
- bizpress
- themesbangkoofree
- TOA
- D4
- eNews
- vulcan
- overtime
- rockwell_v1.0
- vicon
- wideo
- CherryTruffle
- mio
- rttheme13
- Linepress
- DeepFocus
- advanced-newspaper202
- OptimusPrime
- Quadro
- Lumin
- minima
- identity
- U-design.v1.1.2_hkz
- KP
- Petra
- services
- 13FloorTheme.php
- BD
- PolishedTheme
- 13FloorTheme
- kiwinho
- graphix
- jerestate
- centro
- corage
- Reporter
- TheTravelTheme
- XSBasico
- openhouse
- seosurfing1
- bluebaboon
- Newspro-2.8.6
- nd
- zoralime
- GrupoProbeta
- eBusiness
- purplex
- kitten-in-pink
- FashionHouse
- WhosWho
- Deviant
- Bold
- BusinessCard
- EarthlyTouch
- GrungeMag
- LightSource
- Simplism
- TidalForce
- Glow
- Influx
- StudioBlue
- jpmegaph
- redina
- tritone
- dandelion_v2.5
- Bluesky
- ColdStone
- silveroak
- newspro
- GamesAwe
- caratinga.net
- SimplePressTheme
- MyResume
- MyApp
- theme
- bigcity
- dandelion_v2.6.1
- chronicle
- cuizine
- thesis_18
- advanced-newspaper_new
- Event
- wpbedouine
- rt_affinity_wp
- arry12
- backup-TheStyle
- ExploreFeed
- zzzzzzzzz
- Bluemist
- Hermes
- cleartype_v1.0
- polariswp
- Chameleon 1.6
- sniper
- adena
- ariela
- FreshAndClean
- wp-creativix
36 Trackbacks/Pingbacks
- Pingback: TimThumb vulnerability: a big number of Wordpress plugins and themes – themes for wordpress on August 4, 2011
- Pingback: Vulnerabilidades masivas y persistentes « programacion@droope on August 4, 2011
- Pingback: WordPress UK » TimThumb vulnerability: a big number of Wordpress plugins and … on August 4, 2011
- Pingback: TimThumb vulnerability: a big number of Wordpress plugins and … | WordPressPlanet.com on August 4, 2011
- Pingback: TimThumb vulnerability: a big number of Wordpress plugins and … | Wordpress Develop on August 4, 2011
- Pingback: Attention WordPress webmasters, read this! (SECURITY) | HostGator Coupons Code on August 4, 2011
- Pingback: TimThumb vulnerability: a big number of Wordpress plugins and … on August 5, 2011
- Pingback: TimThumb vulnerability: a big number of Wordpress plugins and … – wordpress on August 5, 2011
- Pingback: TimThumb vulnerability: a big number of Wordpress plugins and … – themes for wordpress on August 5, 2011
- Pingback: Some WordPress themes (and other software) vulnerable to “TimThumb” bug | Tiger Technologies Blog on August 9, 2011
- Pingback: Wordpress timthumb.php dosyasında büyük güvenlik açığı | myWordpress | Wordpress ile ilgili her şey on August 9, 2011
- Pingback: Importante vulnerabilidad en TimThumb que afecta a plugins y themes de WP | Seguridad Wordpress - Plugins para Wordpress on August 14, 2011
- Pingback: New Vulnerability in many WordPress themes | TerraNetwork on August 15, 2011
- Pingback: Why does the automated agent copy fail, and how can I copy the … – secure wordpress on August 17, 2011
- Pingback: Wordpresste Önemli Güvenlik Açığı | 32byte on August 18, 2011
- Pingback: Websites Hacked - TimThumb Vulnerability Uncovered in WordPress | WEBphysiology on August 18, 2011
- Pingback: Dikkat! Wordpress Timthumb.php Güvenlik Açığı | AESözlük on August 21, 2011
- Pingback: Get A Security Makeover For Your WordPress Site With WebsiteDefender | .: Tools4Classroom :. on August 24, 2011
- Pingback: Get A Security Makeover For Your WordPress Site With WebsiteDefender on August 25, 2011
- Pingback: Get A Security Makeover For Your WordPress Site With … – wordpress registration plugin on August 25, 2011
- Pingback: Secure steps to take with latest Wordpress attacks (Part One … – secure wordpress on August 26, 2011
- Pingback: Hackers Deserve a Special Place in Hell | Marie Leslie Media on August 26, 2011
- Pingback: Cómo arreglar un wordpress hackeado por el TimThumb.php | Gadgetopost on August 30, 2011
- Pingback: TimThumb vulnerability found in lot of WordPress Themes & Plugins | WordPress Security Patch | Catch Internet on September 6, 2011
- Pingback: TimThumb vulnerability found in lot of WordPress Themes & Plugins … – themes for wordpress on September 6, 2011
- Pingback: TimThumb vulnerability found in lot of WordPress Themes & Plugins … – wordpress themes on September 6, 2011
- Pingback: TimThumb vulnerability found in lot of WordPress Themes & Plugins … – wordpress thems on September 6, 2011
- Pingback: The Trip Overland Hacked via the Timthumb Vulnerability – The Trip on September 18, 2011
- Pingback: The story of the New Nation hack | New Nation on October 5, 2011
- Pingback: Zoroukah – The story of the New Nation hack on October 5, 2011
- Pingback: WordPress Issue? Scan “Local Machine” | Lakeshore Branding on October 10, 2011
- Pingback: Attention WordPress webmasters, read this! (SECURITY) | Web Hosting Promotion Codes on December 13, 2011
- Pingback: Defaced, D*mn! – IMS' Blog on December 20, 2011
- Pingback: TimThumb.php Sicherheits-Update on January 5, 2012
- Pingback: Timthumb Vulnerability Scanner Plugin for WordPress Sites on April 10, 2012
- Pingback: 5 Basic Tips to Increase WordPress Security | CreatiFace.com on April 13, 2013
19 Comments
Post a comment
Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS. Be nice. Keep it clean. Stay on topic. No spam.

I also found it in the FreshAndClean and wp-creativix themes, FYI.
Thanks, I will add them to the list.
Wow… Such a big vulnerability issue.
Thank you for sharing this information.
There seems to be multiple versions of timthumb, out of which some don’t seem to be afftected.
Could you post the md5sum of the affected versions?
these are the md5sums of files I found to be afftected ..
- cfdc880c1f7b940e645e6b79ac4e5c79
- 5b5feeedda04c20f7a2755029c720f01
@Joel.re Yes, there are many versions and variants of timthumb. Just because some plugin/scheme includes timthumb it doesn’t mean that is vulnerable. I’ve seen timthumb versions that don’t include the allowedSites functionality. In the beginning we’ve been thinking to make a list of md5/sha1 hashes and look for those but we quickly realized there are too many variants on the net.
Therefore, we didn’t use hashes. We’ve built a script that will search PHP files for the vulnerable code and report those matching.
This vulnerability is a big one. I work for a medium sized hosting company that implemented mod_security rules to prevent this attack, and our logs show they’re blocking hundreds of separate attempts a day to exploit this.
The mod_security rules are available here if others want to use them: http://blog.tigertech.net/posts/timthumb/
Thanks for MS rules Robert.
BTW, some plugins and themes are renaming timthumb.php to thumb.php. You could adjust the first rule to include that.
Good advice — our logs show some exploit attempts on just “thumb.php”, too. Those are still stopped by the second rule, but we’ve modified the first to match “thumb.php”, too. Thanks!
Hi,
please exclude shortcodes ultimate from list of affected plugins.
It has updated and secure script from 3rd version.
Thanks!
@gn_themes: OK, I’ve removed that script from our list.
What if hackers will use this list to find vulnerable plugins and themes?
@rabbit: Yes, that may happen. This information, like many others, can be used for good or bad. However, I think it’s more important to inform the people that have vulnerable themes and plugins to fix their sites as soon as possible.
Also, WooThemes’ themes seem to be affected, and they have made it really easy to update the file from inside the WP admin area. See more instructions on the WooThemes blog: http://www.woothemes.com/2011/08/timthumb-security-flaw-patch/
Thanks for the information Ethan.
Man am I way late on finding this. I had two of my sites get hacked because of this. Thanks for the information. I’m installing WebsiteDefender WordPress on my sites today. Wish I would have found this out earlier.
Fred
Last completely rewritten code version is here: http://www.binarymoon.co.uk/2011/08/timthumb-2/
They have removed those domains which could be used to exploit (blogspot.com and wordpress.com)
Adal
Hi,
Thanks for sharing.
I don’t know how to say thanks..I have installed the timthumb scanner and removed the out dated plugin.Great article…
Thanks for this article, very informative…I had 5 sites hit with this over the past week and for sure it was TimThumb…the plugin vulnerability scanner fixed it…