CVE Details
Basic Information
| Title |
CVE-2025-4419 |
| Type |
cve |
| Published |
2025-05-22T10:15:55 |
| Last Seen |
2025-05-22T10:22:02 |
CVSS Information
| Base Score |
4.3 (MEDIUM) |
| Attack Vector |
NETWORK |
| Attack Complexity |
LOW |
| Privileges Required |
LOW |
| User Interaction |
NONE |
| Scope |
UNCHANGED |
| Confidentiality Impact |
LOW |
| Integrity Impact |
NONE |
| Availability Impact |
NONE |
AI Analysis
| AI Description |
The Hot Random Image plugin for WordPress is vulnerable to Path Traversal in all versions up to and including 1.9.2. This allows authenticated attackers with Contributor-level access or higher to read arbitrary files on the server by manipulating the ‘path’ parameter. |
| AI Severity |
Medium |
| Vendor |
WordPress Community |
| Product |
Hot Random Image |
| Affected Version |
<=1.9.2 |
Additional Information
| CVE List |
CVE-2025-4419 |
| CWE List |
CWE-22 |
| Bulletin Family |
cve |
Description
The Hot Random Image plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.2 via the 'path' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above,…
CVSS Score Summary
Base Score: %!f(string=#) (MEDIUM)
View Full CVE Details