• Skip to primary navigation
  • Skip to main content
  • Skip to footer
WPSecurityLock – Malware removal & WordPress security services

WPSecurityLock – Malware removal & WordPress security services

WordPress security, malware removal, repair, backups, ongoing maintenance, installation, site migration & support services – WP Security Lock.

  • Facebook
  • LinkedIn
  • Twitter
  • Home
  • About
    • About Us
    • Speaker Information
    • Contact Us by Phone, Email or Live Chat
    • Testimonials
  • Security Services
    • Malware / Virus Removal
    • WordPress Security and Installation Services
    • Monthly Security Packages
    • SSL Conversion Service (HTTP to HTTPS)
  • Blog
  • Resources
  • Contact
  • SafeWP

WordPress Security Tip: Use Timthumb Vulnerability Scanner Plugin

March 11, 2012 By Regina Smola 2 Comments

Timthumb Vulnerability Scanner pluginHelp increase security on your WordPress blog by using the Timthumb Vulnerability Scanner Plugin!

TimThumb is a PHP script that crops, zooms, and resizes images. It's commonly used in WordPress themes and plugins.

This script uses a cache directory from within your wp-content directory to grab and resize your images.

Authors of themes and plugins that use this script name the file timthumb.php or thumb.php (used by Woo Themes), but it could be on your WordPress site with a different name.

Unfortunately, back in August 2011 malicious hackers discovered a backdoor in the TimThumb script and infected a massive number of WordPress sites. This put website owners in a panic! WordPress users were removing themes and plugins, writing articles on how to remove timthumb from their blog, and calling me to fix their hacked WordPress sites.

Luckily, the developers of TimThumb acted quickly to close the backdoor and released TimThumb v 2.8.2 and fixed this security issue. issue.

Here are few theme authors who released a security patch and wrote blog posts to inform customers.

  • Woo Themes – Timthumb (thumb.php) Security Flaw
  • ElegantThemes – Timthumb Vulnerability + Security Update
  • Arras Theme – Zero Day Vulnerability in timthumb script

 Why You Need To Check Your WordPress Blog NOW for TimThumb Vulnerabilities

Some TimThumb scripts have not been updated and people are still getting hacked!

SOLUTION! There's a great plugin called Timthumb Vulnerability Scanner by Peter Butler of http://codegarage.com that will scan your site for outdated timthumb scripts AND update them for you :

This plugin could save your blog's life!!!

I highly recommend you download the Timthumb Vulnerability Scanner at WordPress.org or install the plugin from your Dashboard and run a scan now.

A big shout out to Peter Butler for giving us such a great tool to use!  😀

Here's a quick video I did on Timthumb Vulnerability Scanner.

Have you checked your WordPress blog for any outdated versions of the Timthumb script? Let me know by leaving your comment below.

~ Regina Smola
WordPress Security Expert

Filed Under: WordPress Security Tips Tagged With: best wordpress security plugins, timthumb vulnerability

Reader Interactions

Comments

  1. Scott says

    March 12, 2012 at 9:27 am

    Timthumb Vulnerability Scanner is a fantastic tool, and the latest updates added a new feature for scheduling scans.

    Reply
  2. wparena says

    March 25, 2012 at 10:31 am

    I always got help from your tutorial, this one is also very helpful

    Reply

Leave a Reply to Scott Cancel reply

Your email address will not be published. Required fields are marked *

Let’s work together:

Get in touch with us and send some basic info about your project. Don't be shy, we can help with just about anything.

Contact Us!

Footer

  • Facebook
  • LinkedIn
  • Twitter

Contact

Call 815-600-7270
Contact
Mo,Tu,We,Th,Fr 9:00 am – 5:00 pm

Get WordPress Help Now

Chat With Us!
Submit A Support Ticket

Copyright © 2025 | WP Security Lock, Inc