Hide Real Download Path
Hide Real Download Path has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Hide Real Download Path has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nguyen Xuan Chien. Hide Real Download Path is installed on roughly 90 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.0.38.
CVE-2025-58849Hide Real Download Path <= 1.6 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Hide Real Download Path
Author
Deepak S
Plugin helps you to hide real/direct path of files hosted on your server for download and make your files secure from unauthorized download. It also maintains a log of all downloads done using it and provide capability to disallow direct linking (hot linking) to your files from other website. You can: Allow or restrict hotlink (direct download) of your files from other website/external links. Restrict ‘download only’ from link on your website View log of individual download It support multiple files extensions including: zip / pdf / doc / xls / ppt / exe / gif / png / jpg / jpeg / mp3 / wav / mpeg / mpg / mpe / mov / avi / xlsx *Step by step configuration guideline in Settings sections of plugin after activation Version 1.5 changes: – Corrupt file bug fixed – Easy step by step guide added in admin to configure plugin – Generate Root path dynamically – Support for xlsx added
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C