What is CVE-2026-14333?
CVE-2026-14333 is a vulnerability in the Demi WordPress plugin where full-site backups are stored in a publicly accessible location with predictable filenames and no access protection. This allows unauthenticated attackers to download complete backups, including the site database and user password hashes. Users must update to plugin version 0.0.7 or later.
Azərbaycanca: CVE-2026-14333, Demi WordPress plaginində tam sayt ehtiyat nüsxələrinin (backup) ictimaiyyətə açıq yerdə, proqnozlaşdırıla bilən fayl adı ilə saxlanması zəifliyidir. Bu, autentifikasiya olunmamış hücumçulara verilənlər bazası və istifadəçi parol heşləri daxil olmaqla tam ehtiyat nüsxələrini endirməyə imkan verir. 0.0.7 versiyasından əvvəlki plagin istifadəçiləri dərhal yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What critical data can be accessed through the CVE-2026-14333 vulnerability in the Demi WordPress plugin?
The CVE-2026-14333 vulnerability allows unauthenticated attackers to download complete site backups, including the site database and user password hashes.
What version of the Demi plugin is required to protect against CVE-2026-14333?
To protect against this vulnerability, you must update the Demi plugin to version 0.0.7 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.