A zero-day remote code execution vulnerability has been found in the Webshot feature of the latest shipping version of TimThumb (2.8.13) The flaw could allow hackers to execute commands on vulnerable websites, potentially injecting malicious code. There is currently no official fix for the vulnerability, but we should all have our fingers crossed that an updated version of the plugin is released soon. The developers are miffed that they werent informed about the vulnerability by the researchers who discovered it.”]

