Demi <= 0.0.8 - Unauthenticated Information Exposure to Arbitrary Directory Copy
medium
The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Copy in all versions up to, and including, 0.0.8 via the handle_restore_step function. This is due to missing HTTP access controls on the wp-content/uploads/demi-backup-state/ directory, which exposes...
- CVSS:
- 5.3
- Affected:
- up to 0.0.8
- Fixed in:
- 0.0.9
- Disclosed:
- Jul 27, 2026
CVE-2026-15012 on NVD →
Demi <= 0.0.6 - Unauthenticated Arbitrary Directory Deletion via demi_restore_step AJAX action
critical
The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 0.0.7. The vulnerability exists because the plugin stores its HMAC signing key and per-step restore token as dotfiles inside a publicly accessible subdire...
- CVSS:
- 9.1
- Affected:
- up to 0.0.7
- Fixed in:
- 0.0.9
- Disclosed:
- Jul 27, 2026
CVE-2026-14490 on NVD →
Demi - One Click Demo Import, Backup & Site Migration <= 0.0.6 - Unauthenticated Sensitive Data Exposure
high
The Demi - One Click Demo Import, Backup & Site Migration plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 0.0.6. This is due to backup files stored in a publicly accessible directory with predictable, time-based filenames and an index.php that silenced rather than blocked di...
- CVSS:
- 7.5
- Affected:
- up to 0.0.6
- Fixed in:
- 0.0.7
- Disclosed:
- Jul 13, 2026
CVE-2026-14333 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database