VYPR

Demi

by WordPress

CVEs (2)

  • CVE-2026-14333HigJul 31, 2026
    risk 0.49cvss 7.5epss 0.00

    The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user…

  • CVE-2026-15012MedJul 28, 2026
    risk 0.00cvss 5.3epss 0.00

    The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Copy in all versions up to, and including, 0.0.8 via the handle_restore_step function. This is due to missing HTTP access controls on the…