The BJ Lazy Load plugin v0.7.5 for WordPress has a Remote File Inclusion vulnerability via TimThumb.
id: CVE-2015-9415 info: name: BJ Lazy Load (Timthumb) <= 0.7.5 - Remote File Inclusion author: ...