Description
Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.
Published: 2026-09-17
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated remote code execution vulnerability exists in the Migratico Lite WordPress plugin versions 2.6.8 and older. The flaw permits an attacker to inject and execute arbitrary code within the context of the WordPress site, potentially compromising all files, databases, and services hosted there. The weakness is a classic code injection (CWE-94) and is identified with a CVSS score of 10, the maximum severity.

Affected Systems

The vulnerability affects the superweby Migratico Lite plugin for WordPress. Versions up to and including 2.6.8 are impacted. No other product or version information is provided in the CNA data.

Risk and Exploitability

Given the CVSS rating of 10 and the absence of authentication requirements, the risk is extremely high. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, but the lack of any mitigations in the public description strongly suggests that exploitation could be carried out by any remote actor without credentials. The attack vector is inferred to be through malicious requests to plugin endpoints that process user input without proper validation.

Generated by OpenCVE AI on September 17, 2026 at 22:14 UTC.

Remediation

Vendor Solution

Update the WordPress Migratico Lite Plugin to the latest available version (at least 2.7.1).


OpenCVE Recommended Actions

  • Upgrade the Migratico Lite plugin to version 2.7.1 or newer
  • Disable or remove the plugin if it is not required for site functionality
  • Configure a web application firewall or equivalent security controls to restrict direct access to the plugin’s endpoints and validate all incoming data

Generated by OpenCVE AI on September 17, 2026 at 22:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Superweby
Superweby migratico Lite
Wordpress
Wordpress wordpress
Vendors & Products Superweby
Superweby migratico Lite
Wordpress
Wordpress wordpress

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.
Title WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Superweby Migratico Lite
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-19T02:18:44.706Z

Reserved: 2026-07-13T06:15:10.221Z

Link: CVE-2026-62104

cve-icon Vulnrichment

Updated: 2026-09-19T02:18:39.520Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:15.130

Modified: 2026-09-19T03:17:14.667

Link: CVE-2026-62104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:23Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')