Impact
The Demi WordPress plugin version prior to 0.0.7 stores full‑site backup archives in a publicly accessible location with predictable filenames and no access control, allowing anyone on the internet to download complete backups that contain the site database and user password hashes. This exposes the site's sensitive data, including potentially login credentials and confidential content, to unauthenticated attackers.
Affected Systems
All installations of the Demi plugin v0.0.6 and earlier are affected. The vulnerability is present in any WordPress site that has installed the plugin before the 0.0.7 release.
Risk and Exploitability
The vulnerability can be exploited simply by accessing the predictable URL of the backup file, as no authentication is required. Because the backups contain the full database, compromised password hashes could enable credential stuffing or brute‑force attacks against other services. The CVSS score is not provided, EPSS is unavailable, and the vulnerability is not listed in CISA's KEV catalog, yet the exposure of critical data makes the risk high.
OpenCVE Enrichment