Arbitrary File Upload Vulnerability in Responsive Thumbnail Slider for WordPress
CVE-2015-10144

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 July 2025

What is CVE-2015-10144?

The Responsive Thumbnail Slider plugin for WordPress has a security flaw that allows authenticated users, including those with subscriber-level access, to exploit the image uploader feature. Due to insufficient sanitization of file types, these attackers can upload arbitrary files to the server. This vulnerability can lead to unauthorized remote code execution via a double extension attack, jeopardizing the integrity and security of the affected sites.

Affected Version(s)

Thumbnail carousel slider * < 1.0.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arash Khazaei
.
CVE-2015-10144 : Arbitrary File Upload Vulnerability in Responsive Thumbnail Slider for WordPress