Arbitrary Directory Deletion Vulnerability in Demi Plugin for WordPress
CVE-2026-14490
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-14490?
The Demi β One Click Demo Import, WP Backup & Site Migration plugin for WordPress contains a vulnerability that allows unauthorized users to delete arbitrary directories on the server. The issue arises from the insecure storage of the HMAC signing key and the restoration token in a publicly accessible directory, which lacks adequate protection. An unauthenticated attacker can exploit this weakness by retrieving the exposed HMAC key to forge valid requests, enabling them to execute directory deletion commands without restrictions. This vulnerability highlights the importance of secure coding practices, particularly in protecting sensitive data and ensuring proper access control.
Affected Version(s)
Demi β One Click Demo Import, Backup & Site Migration 0 <= 0.0.7