CVE-2026-14333
Demi - One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticated Sensitive Data Exposure via Public Backup Directory
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.
| Vendor | unknown |
| Product | demi |
| Published | Jul 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown demi
Be the first to know when new unknown vulnerabilities affecting unknown demi are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Demi
0 < 0.0.7
References
Credits
Pavan N WPScan