Demi <= 0.0.6 - Unauthenticated Arbitrary Directory Deletion via demi_restore_step AJAX action
Summary
| CVE | CVE-2026-14490 |
|---|---|
| State | PUBLISHED |
| Assigner | Wordfence |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-28 07:16:40 UTC |
| Updated | 2026-07-28 16:07:15 UTC |
| Description | The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 0.0.7. The vulnerability exists because the plugin stores its HMAC signing key and per-step restore token as dotfiles inside a publicly accessible subdirectory of the WordPress uploads folder — without any `.htaccess` or index file protection — and the `demi_restore_step` AJAX handler, registered for unauthenticated callers, explicitly accepts possession of the on-disk signing key as a standalone alternative to WordPress capability and nonce checks; an unauthenticated attacker who retrieves the exposed key can forge a valid signed state envelope to invoke `CleanDir::execute()` with a caller-supplied absolute path that is subject to no allow-list or path-canonicalization check. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.005090000 probability, percentile 0.405180000 (date 2026-07-29)
Problem Types: CWE-22 | CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Deveasel | Demi One Click Demo Import Backup Site Migration | affected 0.0.7 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.wordfence.com/threat-intel/vulnerabilities/id/63922c28-0cb5-4abe-85ee-20b2c... | [email protected] | www.wordfence.com | |
| plugins.trac.wordpress.org/browser/demi-backup-migration/trunk/classes/Import/Manager.php | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/demi-backup-migration/tags/0.0.6/classes/Backup/Tasks... | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/demi-backup-migration/tags/0.0.6/classes/Import/Manag... | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/demi-backup-migration/trunk/classes/Import/Manager.php | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/demi-backup-migration/tags/0.0.6/classes/Import/Manag... | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/changeset | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/demi-backup-migration/trunk/classes/Backup/Tasks/Clea... | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/demi-backup-migration/trunk/classes/Import/Manager.php | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/demi-backup-migration/tags/0.0.6/classes/Import/Manag... | [email protected] | plugins.trac.wordpress.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Spy0x7 (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-07-07T06:56:07.000Z | Vendor Notified |
| CNA | 2026-07-27T16:39:28.000Z | Disclosed |
There are currently no legacy QID mappings associated with this CVE.