All 3 CVE vulnerabilities found in Hot Random Image, with AI-generated Chinese analysis, references, and POCs.
Vendor: Hot Themes
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-4419 | Hot Random Image <= 1.9.2 - Path Traversal to Authenticated (Contributor+) Limited Arbitrary Image Access via path Parameter CWE-22 | 4.3 | Medium | 2025-05-22 |
| CVE-2025-4405 | Hot Random Image <= 1.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via link Parameter CWE-79 | 4.9 | Medium | 2025-05-22 |
| CVE-2024-29796 | WordPress Hot Random Image plugin <= 1.8.1 - Cross Site Scripting (XSS) vulnerability CWE-79 | 6.5 | Medium | 2024-03-27 |
All 3 known CVE vulnerabilities affecting Hot Random Image with full Chinese analysis, references, and POCs where available.