Hot Themes maintains a narrowly scoped product portfolio centered on the Hot Random Image plugin, which serves a web-based content-delivery function in WordPress and similar environments. The vulnerability disclosures associated with this vendor reflect input-handling and access-control concerns typical of web-facing content plugins, and current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hot Themes over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-29796MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hot Themes Hot Random Image allows Stored XSS.This issue affects Hot Random Im | Mar 27, 2024 | 5.4 | 17 | NO | NO |
CVE-2025-4405MEDIUM The Hot Random Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 1.9.2 due to insufficient inpu | May 22, 2025 | 5.4 | 16 | NO | NO |
CVE-2025-4419MEDIUM The Hot Random Image plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.2 via the 'path' parameter. This makes it possible for authentic | May 22, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hot Themes.
Media articles that mention a CVE ID that affects a product developed by Hot Themes — matched by CVE ID, not by vendor name.