Description
Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration &amp; Cloning <= 6.65 versions.
Published: 2026-09-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to trigger a denial‑of‑service condition in the Migrate Guru – Site Migration & Cloning plugin. By creating specific requests or flooding the site with traffic, the attacker can exhaust server resources, causing the site to become unresponsive or crash. This impact is purely on availability and does not expose data or allow code execution. The weakness corresponds to CWE‑770, indicating a resource exhaustion flaw.

Affected Systems

WordPress sites that install the Migrate Guru plugin version 6.65 or earlier. The plugin, supplied by migrateguru and sourced from the WordPress.org repository, is vulnerable in any installation using these or older versions.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity for availability loss. Because the attack requires no authentication and can be performed against any publicly reachable WordPress installation, the likelihood of exploitation is significant, although a specific EPSS score is not available. The vulnerability is not published in CISA’s KEV catalog. The primary attack vector is the web interface of the affected plugin, accessible through the WordPress admin or front‑end endpoints – this is inferred from the fact that the vulnerability is unauthenticated and centers on plugin functionality.

Generated by OpenCVE AI on September 3, 2026 at 20:31 UTC.

Remediation

Vendor Solution

Update the WordPress Migrate Guru plugin to the latest available version (at least 6.72).


OpenCVE Recommended Actions

  • Update the Migrate Guru – Site Migration & Cloning plugin to version 6.72 or later
  • If an immediate update is not feasible, temporarily deactivate the plugin to eliminate the attack surface
  • Review and remove any lingering temporary migration files or scheduled tasks that might still be accessible, and monitor server resource usage for signs of abuse

Generated by OpenCVE AI on September 3, 2026 at 20:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Migrateguru
Migrateguru migrate Guru – Site Migration &amp; Cloning
Wordpress
Wordpress wordpress
Vendors & Products Migrateguru
Migrateguru migrate Guru – Site Migration &amp; Cloning
Wordpress
Wordpress wordpress

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration &amp; Cloning <= 6.65 versions.
Title WordPress Migrate Guru – Site Migration & Cloning plugin <= 6.65 - Denial of Service Attack vulnerability
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Migrateguru Migrate Guru – Site Migration &amp; Cloning
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-03T16:31:55.358Z

Reserved: 2026-09-02T09:57:48.859Z

Link: CVE-2026-84778

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:28.747

Modified: 2026-09-03T17:25:25.113

Link: CVE-2026-84778

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T15:40:00Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling