CVE-2026-14333 PUBLISHED

Demi - One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticated Sensitive Data Exposure via Public Backup Directory

Assigner: WPScan
Reserved: 01.07.2026 Published: 31.07.2026 Updated: 31.07.2026

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.

Product Status

Vendor Unknown
Product Demi
Versions Default: unaffected
  • affected from 0 to 0.0.7 (excl.)

Credits

  • Pavan N finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE