← WordPress Vulnerabilities
WordPress security by component

Image Hotspot by DevVN

Image Hotspot by DevVN is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Feb 19, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: devvn-image-hotspot

CVE-2025-14445: Image Hotspot by DevVN: Cross-site scripting

Image Hotspot by DevVN is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedFeb 19, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 19, 2026 CVE-2025-14445
Image Hotspot by DevVN: Cross-site scripting
Image Hotspot by DevVN is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Aug 24, 2024 CVE-2024-7656
Image Hotspot by DevVN: Code execution
Image Hotspot by DevVN is affected by code execution. Exploitation requires at least author-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending