Executive brief
Migratico Lite is a WordPress plugin used to migrate website content. This vulnerability allows unauthenticated attackers to execute arbitrary code on affected servers, giving them complete control over websites using the plugin. An attacker could steal customer data, inject malware, deface sites, or use compromised servers to attack other targets.
Technical details
An unauthenticated remote code execution vulnerability exists in Migratico Lite versions 2.6.8 and earlier, classified as an injection vulnerability (OWASP A3). The vulnerability allows attackers to run arbitrary commands on the server without authentication or user interaction. Attack is network-reachable and can be exploited from anywhere in the world. The vulnerability has been patched in version 2.7.1 and later. Patchstack has deployed mitigation rules to block attacks until users patch.
Affected products
- Migratico Migratico Lite ≤ 2.6.8
Timeline
- 2026-09-15: disclosed: Vulnerability published by Patchstack
- 2026-09-15: patched: Patch available in version 2.7.1