WP Engine

Solutions
AgencyEnterpriseSmall & Medium BusinessMarketer
How WP Engine supports marketers.Benefits for marketers.Features that help you innovate.
Developer
How WP Engine supports developers.Benefits for developers.Features that help you move faster.
Explore Our Platform
Insights
Thought LeadershipTopics

Read articles, trends, and insights on these topics from leaders in marketing and technology.

Creative AgilityEnterprise PerformanceActionable IntelligenceEcosystem Integration
Resources

Access ebooks, whitepapers, webinars, and other knowledge from our ecosystem of digital experts.
Visit Resource Center.

Delivering a Slam Dunk Experience on WordPressEbook: The Ultimate Guide to WordPress Plugins15 Common WordPress Mistakes Agencies and their Clients Make
Case Studies
About
Our CompanyOur PlatformLatest News

Access the latest news from inside WP Engine.
Visit the Newsroom.

WP Engine Secures Strategic Growth Investment From Silver LakeWP Engine Unveils First WordPress Digital ExperienceWP Engine Expands Global Presence with New Office in Brisbane
Media Center

Get announcements and resources about WP Engine.

Press Releases
Careers at WP Engine
Pricing
Sales Questions?

Contact Sales

Discover why organizations of all types and sizes choose WP Engine — and how it can benefit you.

Chat

1

I'm available right now to answer any of your questions!

Reply

Call

+1-512-201-4819

Contact

Send a message

Compare Plans
Need Support?
Support DocumentationBilling HelpSupport

We offer support 24 hours a day, 7 days a week, 365 days a year. Log in to get expert one-on-one help.

Log in for support

Sales Questions

Contact Sales

Discover why organizations of all types and sizes choose WP Engine — and how it can benefit you.

Chat

1

I'm available right now to answer any of your questions!

Reply

Call

+1-512-201-4819

Contact

Send a message

Sign in
Sign in
Search

Search

Compare Plans
Call Sales +1-512-201-4819
Menu
AgencyEnterpriseSmall & Medium BusinessMarketers
How WP Engine supports marketers.Benefits for marketersFeatures that help you innovate.
Developers
How WP Engine supports developers.Benefits for developers.Features that help you move faster.
Our PlatformPricingResource CenterOur CompanySolution CenterThought LeadershipDocumentationCareers

Detection and Upgrade of TimThumb Script

Mark Kelnar 11.22.2011

We are turning on a new detection application that will scroll your WP install looking for insecure versions of the TimThumb script.

Why you ask? Because we’ve found that blogs running older versions of TimThumb are more susceptible to malware injections than other blogs running at least version 2.8 of TimThumb.

What are we doing about it? We scan the files in your installation (themes, plugins, etc) regularly. If we find an older, vulnerable, version of TimThumb in your WordPress install, we replace it with the most recent version available, found here, and send you an email.

This helps make the world a safer place.

What about my ALLOWED_SITES configuration?
My custom configurations got blown away. Try defining ALLOW_ALL_EXTERNAL_SITES to TRUE outside of the actual timthumb script. Following the TimThumb instructions, this is done in a file called timthumb-config.php in the same directory as the timthumb script. It looks there for config options.

1) Create a file called timthumb-config.php in the same directory as the timthumb script.
2) Define ALLOW_ALL_EXTERNAL_SITES in that file to true.
3) Create and populate an ALLOWED_SITES array to sites that you want to customize. Like this.

$ALLOWED_SITES = array (
‘flickr.com’,
‘staticflickr.com’,
‘picasa.com’,
‘img.youtube.com’,
‘upload.wikimedia.org’,
‘photobucket.com’,
‘imgur.com’,
‘imageshack.us’,
‘tinypic.com’,
‘last.fm’
);

More WordPress news from WP Engine

Finally: A explanation of HTTPS that non-technical folks can understand!Self-serve error logs now available!

Comments

  1. Johann says

    January 27, 2014 at 2:48 am

    Just finished moving to WP Engine and I can already see the difference in support and reliability.

    Thanks for the update guys.

    Keep up the good work!

    -Johann

    Reply
  2. Richard says

    January 30, 2015 at 12:38 am

    It’s service like this that makes me a happy camper, I would never have found this vulnerability.
    Acting Australia

    Reply
  3. Tim Daniels says

    May 21, 2015 at 3:32 am

    So I’ve just received notification that you have replaced my version automatically.

    Found version 2.8.14 ..Replaced with 2.8.13.1

    Is there a reason why you have downgraded my version?

    Or am I missing something?

    Thanks.

    Reply
  4. Jon says

    January 23, 2017 at 10:47 am

    Same here. They downgraded my version to an older, less secure one. No wonder, as the googlecode.com link mentioned above is dead. The WPEngine “upgrade” script must look for anything that is not version “2.8.13.1” and replace it, **without actually checking** for more recent versions.

    Dumb! Thanks for nothing!

    Reply
  5. Jon says

    January 23, 2017 at 11:16 am

    The version in included with the plugin “Justified Image Grid” is 2.8.14 and includes several additional security fixes. The WPEngine “Auto-replace” re-introduces security flaws that version 2.8.14 removes (I just looked through the actual source code of both versions with WinMerge to highlight all differences and can confirm that the WPEngine version is less secure, as well as breaking the “Justified Image Grid” plugin).

    Also, the most recent version of Tim Thumb is here, and has no security issues:
    https://github.com/tacnoman/thumcno

    Reply
  6. Jon says

    January 23, 2017 at 11:46 am

    Same here. They downgraded my version to an older, less secure one. No wonder, as the googlecode.com link mentioned above is dead. The WPEngine “upgrade” script must look for anything that is not version “2.8.13.1” and replace it, **without actually checking** for more recent versions. This is a very bad idea.

    The version in included with the plugin “Justified Image Grid” is 2.8.14 and includes several additional security fixes. The WPEngine “Auto-replace” re-introduces security flaws that version 2.8.14 removes (I just looked through the actual source code of both versions with WinMerge to highlight all differences and can confirm that the WPEngine version is less secure, as well as breaking the “Justified Image Grid” plugin).

    Also, the most recent version of Tim Thumb is here, and has no security issues:
    https://github.com/tacnoman/thumcno

    P.S. WPEngine Moderators:
    Please respond to this serious problem with your auto-update feature, instead of deleting my very informational comment to you (as you just did).

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Subscribe

    Subscribe to our blog to get great tips for your WordPress site.

  • Favorite Tweets by @wpengine
  • Sign In

    Solutions

    • Agency
    • Enterprise
    • SMB
    • Marketer
    • Developer

    Insights

    • Blog
    • Torque
    • Velocitize

    About

    • Our Company
    • Leadership Team
    • Our Platform
    • Careers
    • Affiliates
    • Contact
    • Legal
    • Newsroom
    • Privacy Policy

    Resources

    • Resource Center
    • Documentation
    • Solution Center
    • Find an Agency

    WP Engine

    504 Lavaca Street, Suite 1000
    Austin, TX 78701

    Sales

    +1-512-201-4819
    [email protected]
    7am–7pm CST

    Billing

    [email protected]

    • Facebook
    • Twitter
    • LinkedIn
    • YouTube
    • Instagram
    • RSS
    © 2013—2026 WPEngine, Inc. All rights reserved.
    WP ENGINE®, VELOCITIZE®, TORQUE®, EVERCACHE®, and the cog logo service marks are owned by WPEngine, Inc.