Impact
The vulnerability allows an unauthenticated attacker to trigger a denial‑of‑service condition in the Migrate Guru – Site Migration & Cloning plugin. By creating specific requests or flooding the site with traffic, the attacker can exhaust server resources, causing the site to become unresponsive or crash. This impact is purely on availability and does not expose data or allow code execution. The weakness corresponds to CWE‑770, indicating a resource exhaustion flaw.
Affected Systems
WordPress sites that install the Migrate Guru plugin version 6.65 or earlier. The plugin, supplied by migrateguru and sourced from the WordPress.org repository, is vulnerable in any installation using these or older versions.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity for availability loss. Because the attack requires no authentication and can be performed against any publicly reachable WordPress installation, the likelihood of exploitation is significant, although a specific EPSS score is not available. The vulnerability is not published in CISA’s KEV catalog. The primary attack vector is the web interface of the affected plugin, accessible through the WordPress admin or front‑end endpoints – this is inferred from the fact that the vulnerability is unauthenticated and centers on plugin functionality.
OpenCVE Enrichment