The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.
https://wpscan.com/vulnerability/df673b6f-2957-460a-b6fe-6e656d9193e0/