WP Original Media Path Security & Risk Analysis

wordpress.org/plugins/wp-original-media-path

Change the location for the uploads folder for WordPress

6K active installs v2.4.2 PHP 7.0+ WP 3.5+ Updated Dec 1, 2025
mediapathsubdomainupload
100
A · Safe
CVEs total1
Unpatched0
Last CVEApr 19, 2023
Safety Verdict

Is WP Original Media Path Safe to Use in 2026?

Generally Safe

Score 100/100

WP Original Media Path has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 19, 2023Updated 4mo ago
Risk Assessment

The wp-original-media-path plugin v2.4.2 presents a generally positive security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates good security practices with 100% of SQL queries using prepared statements and all identified outputs being properly escaped. The lack of file operations, external HTTP requests, and absence of critical taint flows are also strong indicators of a secure codebase in these areas.

However, a significant concern arises from the plugin's vulnerability history. The presence of one known CVE, even if currently patched and of medium severity, indicates that the plugin has had exploitable vulnerabilities in the past. The common vulnerability type being Cross-site Scripting also suggests that input validation and output sanitization, while appearing to be handled correctly in the current static analysis, may have been areas of weakness in previous versions. The fact that a vulnerability was discovered as recently as April 2023 warrants caution. While the current version appears to have addressed past issues, the history itself introduces a degree of risk that should not be overlooked.

In conclusion, while the static analysis of v2.4.2 shows a robustly coded plugin with minimal direct security flaws, the historical context of known vulnerabilities, particularly XSS, tempers this positive assessment. Users should remain vigilant and ensure they are always running the latest version of the plugin, as past issues could potentially re-emerge or new ones could be introduced.

Key Concerns

  • Past vulnerability of medium severity
  • Common vulnerability type: XSS
Vulnerabilities
1

WP Original Media Path Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-23674medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Original Media Path <= 2.4.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings

Apr 19, 2023 Patched in 2.4.1 (279d)
Code Analysis
Analyzed Mar 16, 2026

WP Original Media Path Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

WP Original Media Path Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitwp_original_media_path.php:45
filterplugin_row_metawp_original_media_path.php:48
actionadmin_enqueue_scriptswp_original_media_path.php:50
actionadmin_menuwp_original_media_path.php:52
actionadmin_initwp_original_media_path.php:53
actionadmin_initwp_original_media_path.php:54
actionadmin_initwp_original_media_path.php:55
actionplugins_loadedwp_original_media_path.php:340
Maintenance & Trust

WP Original Media Path Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 1, 2025
PHP min version7.0
Downloads138K

Community Trust

Rating98/100
Number of ratings38
Active installs6K
Developer Profile

WP Original Media Path Developer Profile

RVOLA

3 plugins · 7K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
279 days
View full developer profile
Detection Fingerprints

How We Detect WP Original Media Path

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-original-media-path/assets/wp-original-media-path.css/wp-content/plugins/wp-original-media-path/assets/wp-original-media-path.js
Script Paths
/wp-content/plugins/wp-original-media-path/assets/wp-original-media-path.js
Version Parameters
wp-original-media-path.css?ver=wp-original-media-path.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP Original Media Path