PT-2025-51681 · WordPress · Wp-Responsive-Thumbnail-Slider

Published

2025-07-25

·

Updated

2025-12-16

·

CVE-2015-10144

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Responsive Thumbnail Slider plugin for WordPress versions prior to 1.0.1
Description The software is susceptible to arbitrary file uploads because of inadequate file type validation within the image uploader. Attackers with subscriber-level access or higher can upload arbitrary files to the server using a double extension technique, potentially leading to remote code execution.
Recommendations Update the Responsive Thumbnail Slider plugin to a version newer than 1.0.1.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2015-10144

Affected Products

Wp-Responsive-Thumbnail-Slider