Arbitrary Directory Deletion Vulnerability in Demi Plugin for WordPress
CVE-2026-14490

7.5HIGH

What is CVE-2026-14490?

The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress contains a vulnerability that allows unauthorized users to delete arbitrary directories on the server. The issue arises from the insecure storage of the HMAC signing key and the restoration token in a publicly accessible directory, which lacks adequate protection. An unauthenticated attacker can exploit this weakness by retrieving the exposed HMAC key to forge valid requests, enabling them to execute directory deletion commands without restrictions. This vulnerability highlights the importance of secure coding practices, particularly in protecting sensitive data and ensuring proper access control.

Affected Version(s)

Demi – One Click Demo Import, Backup & Site Migration 0 <= 0.0.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Spy0x7
.