TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the src parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.239
EPSS Ranking 95.8%