Save Your WordPress Site With the Timthumb Vulnerability Scanner and 1-Click Upgrade

Recently, many WordPress sites have been hacked due to a security vulnerability in timthumb.php, a script that is used by hundreds of WordPress themes to resize images.

Oh no! How do I fix it?

The advice that came after the first sites started getting hacked was not the easiest to implement for non-technical WordPress users:

If your WordPress theme is bundled with an unmodified timthumb.php as many commercial and free themes are, then you should immediately either remove it or edit it and set the $allowedSites array to be empty.

This isn’t very helpful if you have no idea where to look or what you’re looking for. The first hurdle is to figure out if you’re affected and then to apply the right fix.

Timthumb Vulnerability Scanner to the Rescue!

If you have no idea what to look for, then the Timthumb Vulnerability Scanner will be a real lifesaver. Install it like any other plugin and it will scan your wp-content directory for vulnerable instances of timthumb.php. It also gives you the option to upgrade your scripts to a safe version with a single click.

The creator of this pugin was overwhelmed with requests to clean up hacks that have exploited the timthumb.php script. He made this plugin incredibly easy to use. If you know how to install a WordPress plugin, then you can manage this. It saves your site in two steps:

1. Scan
Click “Scan” to have the plugin check for the timthumb.php script.

2. Fix
If it finds an outdated and insecure version of the script, you will be given a “Fix” button to click for an instant upgrade.

What if I’ve already been hacked?

The plugin’s author notes that if you’ve already been hacked, this plugin will NOT clean up your site. Essentially, it fixes the door lock, which doesn’t matter if the burglars are already in your house. Believe me, you do not want the hackers to get in there. It can take down your entire server and if your host shuts down your account, you’ll be missing critical traffic and email.

For added security, check out Philip’s post on using a firewall to help protect your WordPress site from attack:

How to Protect Your WordPress Site as Hackers Exploit TimThumb Security Hole

Millions of WordPress sites are still vulnerable to the Timthumb security hack. Don’t let yours be the next victim! Download the Timthumb Vulnerability Scanner and check your sites today.

Featured Plugin - WordPress Membership Site Plugin

If you're thinking about starting a paid, or just private, membership site then this is truly the plugin you've been looking for. Easy to use, massively configurable and ready to go out of the box!
Find out more

Featured Plugin - WordPress Newsletter Plugin

Now there's no need to pay for a third party service to sign up, manage and send beautiful email newsletters to your subscriber base - this plugin has got the lot.
Find out more

Featured Plugin - WordPress Infinite SEO Plugin

Fully integrated with the SEOMoz API, complete with automatic links, sitemaps and SEO optimization of your WordPress setup - this is the only plugin you need to help you rank your site number 1 on Google - nothing else compares.
Find out more

Featured Plugin - WordPress Google Maps Plugin

Simply insert google maps into posts, sidebars and pages - show directions, streetview, provide image overlays and do it all from a simple button and comprehensive widget.
Find out more

Featured Plugin - WordPress Ecommerce Shopping Cart Plugin

Out of all the WordPress ecommerce plugins available, MarketPress has got to be the winner - easy to configure, powerful functionality, multiple gateways and more. A simply brilliant plugin!
Find out more

Featured Plugin - WordPress Appointments Plugin

Take, set and manage appointments and client bookings without having to leave WordPress. Appointments+ makes it easy.
Find out more

Featured Plugin - WordPress Pop-Up Chat Plugin

No javascript required, no third part chat engine, just fully featured chat right in your own database on your own WP sites - couldn't be easier.
Find out more

Featured Plugin - WordPress Q&A Site Plugin

It's now incredibly easy to start your own Q&A site using nothing more than WordPress - The Q&A plugin simply and brilliantly transforms any site, or page, into a perfect support or Q&A environment.
Find out more

Featured Plugin - WordPress Wiki Plugin

To get a wiki up and running you used to need to install Mediawiki and toil away for days configuring it... not any more! This plugin gives you *all* the functionality you want from a wiki, in WordPress!!!
Find out more

Comments (9)

  1. I had to ask my hosting to whitelist timthumb on my domain so that a theme would work. But looking for more info on timthumb, discovered it was a spot for hackers. Thanks for calling my attention to “Timthumb Vulnerability Scanner”. I will install it on all sites I have control.

  2. I never got hacked, but I was scared anyways … I did what you said and it acts as if all was successful. So thanks very much, easy solution! Now here’s to hoping 2.8.2 doesnt become vulnerable

Participate