CVE-2026-14333: Unknown Demi

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.

Affected products

  • Unknown Demi: before 0.0.7 (fixed in 0.0.7)

Published 2026-07-31. Last modified 2026-08-26.