Professional WordPress Themes

Aug 20, 2011

TimThumb Security

A couple of weeks ago a security flaw was found in TimThumb – the script we use to resize images in our themes.

TimThumb is actually an invention of our own – something we originally developed for Mimbo Pro. As soon as the flaw was discovered I set to work fixing as many issues as I could. In the following week I committed at least half a dozen security improvements. The person who announced the issues went so far as to rewrite TimThumb introducing even more new security features.

To ensure that TimThumb is up to date on your website you should either:

  1. Update your theme from the accounts control panel
  2. Update TimThumb from the Google Code site

The version of TimThumb used on Pro Theme Design themes is always up to date. For releasing theme updates I created a build script. A file that zips up the theme files, updates the translation files, creates the right to left css file for rtl languages, and then updates TimThumb from the latest Google Code source file.

Security has always been a concern with TimThumb and now that there is an extra pair of eyes helping with the code it will be an even higher priority and kept as strong as possible.

6 Comments Leave a comment ›

  1. Please send me a copy of the latest TimThumb release so I can replace the old file.

    Also send instructions.

    Thank you,

    Clifford Chentnik

  2. So if I buy the new mimbo pro will i receive the theme with already updated and secure timthumb script?

    You can reply directly to this email if don’t want this be visible.

    Thanks

    • TimThumb was updated in all Pro Theme Design themes as soon as the exploit was found. Any theme you purchase will have the latest version and be as secure as can be.

  3. timthumb.googlecode.com/svn/trunk/timthumb.php ..
    Latest TimThumb release… Right?

Leave a Response

About Us

Pro Theme Design began in 2007 as a collaboration between two web designers...

Darren Hoyt
Darren Hoyt

Charlottesville, VA, USA

Established in the WordPress community for projects like Mimbo and Agregado, Darren also has 14 years experience designing websites for businesses and startups. His role at Pro Theme is taking what Ben builds and making it beautiful and simple to use.

Ben Gillbanks
Ben Gillbanks

Exeter, England, UK

Ben is a WordPress ninja, best known for creating Regulus. More recently he took over the development of the image-resize script TimThumb. He spends his time at Pro Theme Design turning Darren's ideas into reality.

Email us general questions or visit the support section with product questions.