Tag
medium
advisory
The Demi WordPress Plugin Vulnerable to Arbitrary Directory Deletion (CVE-2026-14490)
2 TTPs 1 CVEUnauthenticated attackers can exploit CVE-2026-14490 in The Demi - One Click Demo Import, WP Backup & Site Migration WordPress plugin (versions up to and including 0.0.7) to achieve arbitrary directory deletion by retrieving a publicly exposed HMAC signing key and forging valid requests to a vulnerable AJAX handler.
The Demi – One Click Demo Import, WP Backup & Site Migration plugin <= 0.0.7
wordpress
plugin-vulnerability
arbitrary-deletion
web-vulnerability
2t
1c
critical
threat
CVE-2026-8380: WordPress Frontend File Manager Arbitrary Post Deletion
2 rules 1 TTPCVE-2026-8380 is a critical authorization bypass vulnerability in the WordPress Frontend File Manager plugin <= 23.6 that allows authenticated low-privilege users, or unauthenticated users with guest uploads enabled, to permanently delete arbitrary WordPress posts, pages, attachments, and custom post types.
Frontend File Manager
cve
wordpress
authorization
privilege-escalation
arbitrary-deletion
plugin-vulnerability
2r
1t