Executive brief
Migrate Guru is a popular WordPress plugin used to migrate and clone websites between servers. An unauthenticated attacker can exploit a vulnerability in versions 6.65 and earlier to cause a denial of service, making the site slow or temporarily unavailable. No authentication or user interaction is required to mount this attack.
Technical details
The vulnerability is a denial of service flaw in Migrate Guru versions 6.65 and earlier that does not require authentication to exploit. The attack vector is network-based, allowing a remote attacker to overwhelm the plugin with requests or trigger resource-intensive operations without credentials. The exact technical mechanism is not disclosed in the advisory, but the impact is degraded site performance or complete service unavailability. The fix is available in version 6.72 and later.
Affected products
- Migrate Guru Migrate Guru – Site Migration & Cloning 6.65 and earlier
Timeline
- 2026-09-03: disclosed: Vulnerability published on NVD
- 2026-09-02: patched: Fix released in version 6.72
- 2026-08-28: other: Vulnerability reported by Ananda Dhakal (Patchstack)