CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-15012

mediumCVSS 5.3covered by 1 sourcefirst seen 2026-07-28
The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Copy in all versions up to, and including, 0.0.8 via the handle_restore_step function. This is due to missing HTTP access controls on the wp-content/uploads/demi-backup-state/ directory, which exposes the cryptographic restore key used to both authenticate the unauthenticated AJAX handler and forge signed restore-state envelopes. This makes it possible for unauthenticated attackers to copy arbitrary files to attacker-controlled destinations on the server. An active restore operation must have been initiated, which writes the .restore_key and .restore_step_token files to the public upload directory, before the exposed secrets can be harvested and chained to achieve unauthenticated arbitrary file copy.

⚡ Watch CVE-2026-15012

Get an email if CVE-2026-15012 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-15012

CVE.org record

Embed the live status

CVE-2026-15012 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-15012 status](https://www.csirts.com/badge/CVE-2026-15012)](https://www.csirts.com/cve/CVE-2026-15012)