CVE-2011-4106 describes a critical vulnerability in TimThumb (timthumb.php) versions prior to 2.0, affecting various WordPress plugins that utilize this library. The flaw allows remote attackers to upload and execute arbitrary code by manipulating the 'src' parameter with a whitelisted domain, bypassing validation. With a CVSS score of 6.8, this vulnerability is of medium severity, requiring moderate attack complexity but enabling full confidentiality, integrity, and availability compromise. Exploitation has been observed in the wild, with public exploit code available on ExploitDB, though it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.99CPE matchmatch criteria | cpe:2.3:a:binarymoon:timthumb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.