Impact
The Hot Random Image plugin allows an authenticated contributor or higher to insert malicious web scripts via the link parameter. The input is stored in the database and later output without proper sanitization, causing injected scripts to execute whenever a user views the affected page. This stored XSS can be leveraged for defacement, credential theft, or intrusion of user accounts, affecting confidentiality, integrity and availability for all site visitors.
Affected Systems
WordPress sites running the Hot Random Image plugin by Hot Themes, any version up to and including 1.9.2.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.9 and an EPSS score below 1%, indicating a moderate severity and a very low probability of exploitation in the wild. It is not listed in CISA’s KEV catalog. Attackers must first authenticate with at least Contributor privileges and then submit a crafted link value to a page. Because the attack requires authenticated access and the injected payload executes in users’ browsers, the risk is confined but potentially wide‑ranging for sites with many visitors.
OpenCVE Enrichment
EUVD