Feed/CVE-2026-14333
CVE-2026-14333HIGHCVSS 7.5

CVE-2026-14333

Published Jul 31, 2026·Updated Jul 31, 2026

NVD Description

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free