Unrated severityNVD Advisory· Published Jul 31, 2026· Updated Jul 31, 2026
Demi - One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticated Sensitive Data Exposure via Public Backup Directory
CVE-2026-14333
Description
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <0.0.7
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/df673b6f-2957-460a-b6fe-6e656d9193e0/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.