CVE-2026-15012 | deveasel Demi Plugin up to 0.0.8 on WordPress AJAX handler demi-backup-state handle_restore_step access control

SecurityVulns

A vulnerability was found in deveasel Demi Plugin up to 0.0.8 on WordPress. It has been rated as critical. Affected is the function handle_restore_step of the file wp-content/uploads/demi-backup-state of the component AJAX handler. The manipulation leads to improper access controls.

This vulnerability is traded as CVE-2026-15012. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More