cxsecurity.com
https://cxsecurity.com/issue/WLB-2015080170 CVE-2015-10144
HIGH
Responsive Thumbnail Slider < 1.0.1 - Authenticated (Subscriber+) Arbitrary File Upload
Record summary
CVE-2015-10144 has a selected CVSS score of 8.8 (high); EIP currently links 2 catalogued exploits.
Description
The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sanitization in the via the image uploader in versions up to 1.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected sites server using a double extension which may make remote code execution possible.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 25, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Thumbnail carousel sliderBrowse nik00726 / Thumbnail carousel sliderDefault status: unaffected | CVE List | Before 1.0.1 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBWordPress Plugin Responsive Thumbnail Slider 1.0 - Arbitrary File UploadExploitDB exploitby Arash KhazaeiNot analyzed1 file
MetasploitWordPress Responsive Thumbnail Slider Arbitrary File UploadMetasploit exploitby Arash Khazaei +1 moreNot analyzed1 file
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-10144 raw.githubusercontent.com
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/wp_responsive_thumbnail_slider_upload.rb acunetix.com
https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-thumbnail-carousel-slider-arbitrary-file-upload-1-0 exploit-db.com
https://www.exploit-db.com/exploits/37998 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/6c396ae6-d34c-4554-b670-28868dc136a5?source=cve