There is been a lot of talk online last week about thew newly discovered TimThumb vulnerability in versions before 1.34. I see that you haven't addressed this issue yet, since the version that's included into the plugin is 1.15. Please review these instructions and make the adjustments to the script or update to the most current version http://www.websitedefender.com/web-security/timthumb-vulnerability-wordpress-plugins-themes/
http://code.google.com/p/timthumb/
@Maxchirkov: Thanks for the update. Just to update our users, we are using TimThumb version 2.7, with our latest plugin update 4.1.1.
In case you have not updated vSlider 4.0+, please update it to version 4.1.1 in case you face any issues we will help you out at
http://www.vibethemes.com/forum/
Thanks,
( v )
amandascookin
Member
Posted 1 year ago #
I have posted a problem with the new 4.1.1 version over at your forums. It's working fine on one of my site but not on the other. On the other I am using the option to pull the image from the first image in the post and using posts from a specific category. The text shows but the images have all disappeared. Now instead of it rotating through images, there's 4 boxes of titles and texts. Almost looks like a google ad! :-( It was working perfectly before I upgraded. http://secretrecipeclub.com/ please help!
FYI: The current version of timthumb is now 2.8.3, you may want to update your plugin to the latest version.
http://timthumb.googlecode.com/svn/trunk/timthumb.php
Changes are here:
http://code.google.com/p/timthumb/source/list