A tiny image-resizing script bundled into hundreds of premium WordPress themes became one of the most exploited vulnerabilities in WordPress history. Here's what happened and what to do.
TimThumb is a small PHP script — a single file, timthumb.php — designed to dynamically resize and crop images. It became extremely popular with WordPress theme developers because it made it easy to display images at specific dimensions without requiring the site owner to prepare images manually. By 2011 it was bundled into hundreds of premium themes sold through marketplaces like ThemeForest.
In August 2011, a critical security flaw was discovered in TimThumb versions prior to 2.0. The script was designed to fetch images from a whitelist of trusted domains — including img.youtube.com, img.blogger.com, and others. The flaw was in how it validated that a URL belonged to a trusted domain.
The validation simply checked whether the trusted domain name appeared anywhere in the URL. An attacker could craft a URL like http://evil.com/img.youtube.com/malicious.phpand TimThumb would accept it, download the file, and cache it on your server. By embedding PHP code in an image file, attackers could plant executable files on your web server and run arbitrary commands — effectively giving them full control of your site.
The exploit was simple, widely documented, and automated within days of disclosure. Tens of thousands of WordPress sites were compromised.
Any theme or plugin that bundled timthumb.php version 1.x was vulnerable. This included a very large number of themes sold through ThemeForest and other commercial theme marketplaces. The official TimThumb page listed over 19 million downloads at the time.
The problem was compounded by the distribution model. Many themes bundled timthumb.php directly in their theme files rather than using a plugin. When TimThumb released version 2.0 with the fix, site owners had to update their theme specifically — there was no central WordPress update mechanism that would catch it.
The simplest check is to search your WordPress installation for timthumb.php:
wp-content/themes folder for any file named timthumb.phpAlso check wp-content/plugins — some plugins bundled TimThumb as well.
If you find a vulnerable version, download the latest timthumb.php from the official source and replace the file in your theme folder. Version 2.0 addressed the core vulnerability. After updating, also check your server's TimThumb cache directory (usually calledcache inside your theme folder) for any suspicious .php files that may have been planted before you patched.
If your site was already compromised, a file replacement isn't sufficient — backdoor files may have been planted elsewhere. A full site scan and database check is warranted.
The TimThumb incident highlighted the risk of third-party code bundled into themes and plugins. A vulnerability in a utility script that theme developers had no reason to monitor could compromise every site using that theme. It accelerated the push for keeping WordPress components updated — not just core, but everything running on your installation.
It also reinforced a principle that remains true: the attack surface of a WordPress site is as large as the sum of everything running on it. Every script, every plugin, every theme is a potential entry point.
Australian WordPress hosting from $5/month
Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.