๐Ÿ” CVE Alert

CVE-2026-14333

UNKNOWN 0.0

Demi - One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticated Sensitive Data Exposure via Public Backup Directory

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.

Vendor unknown
Product demi
Published Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for unknown demi

Be the first to know when new unknown vulnerabilities affecting unknown demi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Demi
0 < 0.0.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/df673b6f-2957-460a-b6fe-6e656d9193e0/

Credits

Pavan N WPScan