CVE-2026-84778
largeUnauthenticated Denial-of-Service in Migrate Guru WordPress Migration Plugin
CVE-2026-84778 is an unauthenticated denial-of-service flaw in the Migrate Guru – Site Migration & Cloning WordPress plugin, caused by allocation of resources without limits or throttling (CWE-770). Because it requires no privileges or user interaction and is reachable over the network (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), any attacker who can reach the affected site can trigger excessive resource consumption and disrupt availability. A successful attack does not disclose or alter data (C:N/I:N) but can render the site unavailable (A:H), which matters for sites running migrations or revenue-generating operations. Any WordPress site with Migrate Guru version 6.65 or earlier active is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS puts 30-day exploitation probability at roughly 0.3%.
What to do: Sites running Migrate Guru 6.65 or earlier should update to the latest patched release published after 6.65 (check the vendor changelog for the fixed version). If updating is not immediately possible, deactivate the plugin when no migration is in progress, or apply WAF/rate-limiting rules to restrict the plugin's unauthenticated endpoints. Since exploitation attempts may spike if a public PoC emerges, monitor vendor advisories and your WAF logs for unauthenticated request bursts against the plugin.
| Migrate Guru (WordPress plugin) Migrate Guru – Site Migration & Cloning | <= 6.65 (all versions up to and including 6.65) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-770
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.