Timber
Timber has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Dependency On Vulnerable Third-Party Component, behind 1 of the records (50%). Other recurring categories include Deserialization Of Untrusted Data.
Every one of the 2 issues recorded for Timber has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Trình Vũ. Timber is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2024-29800Timber <= 1.23.0 - Authenticated (Admin+) PHP Object Injection
Read the full analysisVulnerability Records

Timber
Author
jarednova
With the upcoming release of Timber 2.0, we will not release a 2.0 version and beyond as a plugin, but only as a Composer package. We advise everyone to switch to the Composer based install as soon as possible. You will find an extensive list with guides and the reasons why we are not going to release Timber 2.0 as a plugin anymore. Switching to the Composer based version Announcement: Dropping support for the plugin version of Timber Guide: How do I switch over from the plugin version to the Composer based version of Timber? Backstory: Why we are dropping support for the plugin in the first place GitHub issue: Roadmap for Timber 2.0 Timber helps you create fully-customized WordPress themes faster with more sustainable code. With Timber, you write your HTML using the Twig Template Engine separate from your PHP files. This cleans up your theme code so, for example, your PHP file can focus on being the data/logic, while your Twig file can focus 100% on the HTML and display. Once Timber is installed and activated in your plugin directory, it gives any WordPress theme the ability to take advantage of the power of Twig and other Timber features. Want to learn more? Project Page Timber on GitHub Looking for Documentation? Timber Documentation Twig Reference (from SensioLabs) Twig is the template language powering Timber; if you need a little background on what a template language is, Twig’s homepage has an overview Video Tutorials Overview / Getting Started Guide Need support? StackOverflow is for usage questions and troubleshooting GitHub issues are for reporting bugs and errors Support Please post on StackOverflow under the “Timber” tag. Please use GitHub issues only for specific bugs, feature requests and other types of issues.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C