CVE-2026-14333

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-31 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-14333

Mitre link : CVE-2026-14333

CVE.ORG link : CVE-2026-14333


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management