High severity8.8NVD Advisory· Published Jul 25, 2025· Updated Jun 17, 2026
CVE-2015-10144
CVE-2015-10144
Description
The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sanitization in the via the image uploader in versions up to 1.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected sites server using a double extension which may make remote code execution possible.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <=1.0.1
- nik00726/Thumbnail carousel sliderv5Range: 0
Patches
Vulnerability mechanics
References
5- cxsecurity.com/issue/WLB-2015080170nvdExploit
- raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/wp_responsive_thumbnail_slider_upload.rbnvdExploit
- www.exploit-db.com/exploits/37998nvdExploit
- www.wordfence.com/threat-intel/vulnerabilities/id/6c396ae6-d34c-4554-b670-28868dc136a5nvdThird Party Advisory
- www.acunetix.com/vulnerabilities/web/wordpress-plugin-thumbnail-carousel-slider-arbitrary-file-upload-1-0/nvdTechnical Description
News mentions
1- Weekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer EnumRapid7 Blog · Jun 5, 2026