PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2015-9415

7.5
CVSS
Description

The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Updated Sep 18, 2026View on NVD →
S4E scanner

BJ Lazy Load (Timthumb) <= 0.7.5 - Remote File Inclusion

The BJ Lazy Load plugin v0.7.5 for WordPress has a Remote File Inclusion vulnerability via TimThumb. References: https://wpscan.com/vulnerability/c15aef94-822d-40eb-80a6-e4a0611cb5c1/ https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bj-lazy-load/bj-lazy-load-10-remote-file-inclusion-via-timthumb https://nvd.nist.gov/vuln/detail/CVE-2015-9415 Remediation: Fixed in 1.0

Used 2.3k times · domain, subdomain, ipv4

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →