What is CVE-2026-15012?
This vulnerability exists in the Demi plugin for WordPress, affecting all versions up to and including 0.0.8. It allows Arbitrary Directory Copy via the `handle_restore_step` function due to missing HTTP access controls on the `wp-content/uploads/demi-backup-state/` directory. Users are advised to update the plugin immediately.
Azərbaycanca: Bu zəiflik WordPress üçün Demi pluginində aşkarlanıb və 0.0.8 daxil olmaqla bütün versiyalara təsir edir. `handle_restore_step` funksiyası vasitəsilə `wp-content/uploads/demi-backup-state/` qovluğunda HTTP giriş nəzarətinin olmaması səbəbindən ixtiyari qovluq kopyalamağa imkan verir. İstifadəçilərə pluginini dərhal yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress plugin is affected by CVE-2026-15012?
This vulnerability affects the Demi plugin for WordPress.
What should users do to protect against CVE-2026-15012?
Users are advised to update the Demi plugin immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.