Timber <= 1.23.1 - Use of a Vulnerable Dependency

2025-07-24 00:00
Anonymous

Strategic Overview

Status
Patched in 1.23.3
Affected PluginTimber
Affected Version<= 1.23.1
CVSS6.5Medium
CVECVE-2024-45411
View all Timber vulnerabilities

Vulnerability Overview

The Timber plugin for WordPress is utilizing a vulnerable version of Twig in all versions up to, and including, 1.23.1. It has not been confirmed if the package is exploitable in the plugin.

Technical Analysis

REMEDIATION: Update to version 1.23.3, or a newer patched version --- IDENTIFIER: CWE-1395 (Dependency on Vulnerable Third-Party Component) The product has a dependency on a third-party component that contains one or more known vulnerabilities.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C