Hot Random Image
Hot Random Image has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 5.2, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Path Traversal.
Every one of the 3 issues recorded for Hot Random Image has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, most of them (2) reported by Kishan Vyas. Hot Random Image is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2024-29796Hot Random Image <= 1.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Hot Random Image
Author
Hot Themes
Hot Random Image by Hot Themes is a basic plugin that shows a randomly picked image from a selected folder where images are stored. You can define a folder and the plugin will show all the images from this folder in a random order. Also, it’s possible to select only certain images from the folder that will be added in rotation. Each image can be linked. Alt text is optional. Image dimensions (width and height) can be defined in any format (pixels, percents, auto-mode…). Therefore, this plugin is appropriate for all responsive websites.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C