Junglewise Threat Intelligence

CVE-2026-84778: Migrate Guru unauthenticated denial of service

CVE-2026-84778 · Severity: high · CVSS 7.5 · Published 2026-09-03

Executive brief

Migrate Guru is a popular WordPress plugin used to migrate and clone websites between servers. An unauthenticated attacker can exploit a vulnerability in versions 6.65 and earlier to cause a denial of service, making the site slow or temporarily unavailable. No authentication or user interaction is required to mount this attack.

Technical details

The vulnerability is a denial of service flaw in Migrate Guru versions 6.65 and earlier that does not require authentication to exploit. The attack vector is network-based, allowing a remote attacker to overwhelm the plugin with requests or trigger resource-intensive operations without credentials. The exact technical mechanism is not disclosed in the advisory, but the impact is degraded site performance or complete service unavailability. The fix is available in version 6.72 and later.

Affected products

  • Migrate Guru Migrate Guru – Site Migration & Cloning 6.65 and earlier

Timeline

  • 2026-09-03: disclosed: Vulnerability published on NVD
  • 2026-09-02: patched: Fix released in version 6.72
  • 2026-08-28: other: Vulnerability reported by Ananda Dhakal (Patchstack)

References