Timber <= 1.23.1 - Use of a Vulnerable Dependency
2025-07-24 00:00
AnonymousStrategic Overview
Vulnerability Overview
The Timber plugin for WordPress is utilizing a vulnerable version of Twig in all versions up to, and including, 1.23.1. It has not been confirmed if the package is exploitable in the plugin.
Technical Analysis
REMEDIATION: Update to version 1.23.3, or a newer patched version --- IDENTIFIER: CWE-1395 (Dependency on Vulnerable Third-Party Component) The product has a dependency on a third-party component that contains one or more known vulnerabilities.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C