Hide Real Download Path

Hide Real Download Path has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Hide Real Download Path has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by Nguyen Xuan Chien. Hide Real Download Path is installed on roughly 90 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.0.38.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Hide Real Download Path vulnerabilities before they are exploited.

Most severe open issueCVSS 4.3CVE-2025-58849

Hide Real Download Path <= 1.6 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Hide Real Download Path banner
Latestv1.6

Hide Real Download Path

Deepak S

Author

Deepak S

3.8(14)
76/100
Last Updated
2014-10-20 (12y ago)
Active Installs
90+
Downloads
10,904
Requires WP
3.5+
Requires PHP
0+
Tested up to
WP 4.0.38
Created
2013-01-15 (14y ago)

Plugin helps you to hide real/direct path of files hosted on your server for download and make your files secure from unauthorized download. It also maintains a log of all downloads done using it and provide capability to disallow direct linking (hot linking) to your files from other website. You can: Allow or restrict hotlink (direct download) of your files from other website/external links. Restrict &#8216;download only’ from link on your website View log of individual download It support multiple files extensions including: zip / pdf / doc / xls / ppt / exe / gif / png / jpg / jpeg / mp3 / wav / mpeg / mpg / mpe / mov / avi / xlsx *Step by step configuration guideline in Settings sections of plugin after activation Version 1.5 changes: – Corrupt file bug fixed – Easy step by step guide added in admin to configure plugin – Generate Root path dynamically – Support for xlsx added

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C