ZeroHour

CVE-2026-84778

large

Unauthenticated Denial-of-Service in Migrate Guru WordPress Migration Plugin

CVSS 3.1
7.5 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-84778 is an unauthenticated denial-of-service flaw in the Migrate Guru – Site Migration & Cloning WordPress plugin, caused by allocation of resources without limits or throttling (CWE-770). Because it requires no privileges or user interaction and is reachable over the network (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), any attacker who can reach the affected site can trigger excessive resource consumption and disrupt availability. A successful attack does not disclose or alter data (C:N/I:N) but can render the site unavailable (A:H), which matters for sites running migrations or revenue-generating operations. Any WordPress site with Migrate Guru version 6.65 or earlier active is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS puts 30-day exploitation probability at roughly 0.3%.

What to do: Sites running Migrate Guru 6.65 or earlier should update to the latest patched release published after 6.65 (check the vendor changelog for the fixed version). If updating is not immediately possible, deactivate the plugin when no migration is in progress, or apply WAF/rate-limiting rules to restrict the plugin's unauthenticated endpoints. Since exploitation attempts may spike if a public PoC emerges, monitor vendor advisories and your WAF logs for unauthenticated request bursts against the plugin.

Affected
Migrate Guru (WordPress plugin) Migrate Guru – Site Migration & Cloning<= 6.65 (all versions up to and including 6.65)
Estimated exposure
largeon the order of tens of thousands to ~200,000 sites — Migrate Guru has historically shown on the order of 200,000 active installs on WordPress.org, but because the plugin is often installed only temporarily to perform a migration, the number of sites with it currently active and exposing the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions.

Ecosystems
WordPress
Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.