Skip to content

Comment on Zero Day Vulnerability in many Wordpress Themes

Comments

My WP theme is from WooThemes and it includes "thumb.php" which upon inspection is timthumb.php. The blog post says to patch this you should remove the list from the allowedSites variable which I have done... I'll look at this more tomorrow but just FYI!

Errm, you should probably do that today - and check for the presence of base64 encoded images - now that you told the world about it ;)

Did that too.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.