Input validation vulnerability in Timthumb Vulnerability Scanner 1.54

The Timthumb Vulnerability Scanner plugin for WordPress is not secure in versions up to, and including, 1.54. This means that someone who is not authenticated can make a fake request and, if the WordPress administrator is tricked into doing something such as clicking on a link, the scan is activated. To help protect against this, nonce validation needs to be added to the admin_panel_controller() function.

Detected in:

Timthumb Vulnerability Scanner open vulnerable versions: >= * <= 1.54

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.