S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Sep 30, 2025

CVE-2015-9415 Scanner

CVE-2015-9415 Scanner - Remote File Inclusion (RFI) vulnerability in BJ Lazy Load

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.9k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2015-9415
7.5
CVSS

The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

BJ Lazy Load is a popular plugin for WordPress, a widely used content management system for websites. The plugin is designed to enhance the loading times of websites by lazy loading images and other content, deferring their loading until they enter into the viewport. This makes websites run more efficiently for end-users, especially on mobile devices with slower connections. Website developers and administrators primarily use BJ Lazy Load to optimize site performance. It is frequently updated to align with the latest WordPress versions and web development best practices. BJ Lazy Load aims to improve user experience and SEO rankings by cutting down on loading times.

The vulnerability found in BJ Lazy Load is a Remote File Inclusion (RFI), which is a critical security flaw. An RFI vulnerability allows remote attackers to include files from a different server, which can be executed in the vulnerable server's environment. The flaw found in the version 0.7.5 centers around the plugin's misuse of the TimThumb script, which doesn't fully validate or sanitize inputs. This leads to attackers potentially executing arbitrary code or stealing information. It poses significant security risks to websites relying on BJ Lazy Load if left unpatched.

Technical details about this vulnerability reveal that the vulnerable endpoint is the "thumb.php" script within the BJ Lazy Load plugin. This script improperly handles the "src" parameter, enabling remote file inclusion. Attackers craft a URL that points to a malicious source via this parameter, leading the server to fetch and potentially execute an unauthorized file. The vulnerability is confirmed when the server responds with specific error messages or includes external images. Proper exploitation of the vulnerable parameter can let attackers execute scripts in the WordPress environment remotely.

If exploited, this RFI vulnerability can have severe consequences, ranging from unwanted code executions to full server compromises. Malicious actors could include scripts that steal user data, compromise sensitive information, or even enhance their access privileges. This could degrade the website's performance and reliability, causing further damage to the brand reputation and user trust. Additionally, infected sites may become vectors for further attacks on site visitors. Ensuring timely patch management is critical to minimizing these risks.

REFERENCES

Solution Advice
  • Upgrade BJ Lazy Load to version 1.0 or later to remove the vulnerability.
  • Regularly monitor the plugins used on your WordPress site, ensuring they receive timely updates.
  • Avoid using or retain any outdated plugins that contain known vulnerabilities.
  • Implement a web application firewall to detect and prevent attempts of RFI.
  • Conduct periodic security audits to discover and mitigate other potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.