Impact
An unauthenticated remote code execution vulnerability exists in the Migratico Lite WordPress plugin versions 2.6.8 and older. The flaw permits an attacker to inject and execute arbitrary code within the context of the WordPress site, potentially compromising all files, databases, and services hosted there. The weakness is a classic code injection (CWE-94) and is identified with a CVSS score of 10, the maximum severity.
Affected Systems
The vulnerability affects the superweby Migratico Lite plugin for WordPress. Versions up to and including 2.6.8 are impacted. No other product or version information is provided in the CNA data.
Risk and Exploitability
Given the CVSS rating of 10 and the absence of authentication requirements, the risk is extremely high. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, but the lack of any mitigations in the public description strongly suggests that exploitation could be carried out by any remote actor without credentials. The attack vector is inferred to be through malicious requests to plugin endpoints that process user input without proper validation.
OpenCVE Enrichment