Sceawere

Vulnerability Detail

CVE-2026-84778UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Migrate Guru Unauthenticated DoS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
4h ago
Vendor
migrateguru
Product
Migrate Guru – Site Migration & Cloning
Attack Type
CWE-770 Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration &amp; Cloning <= 6.65 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-03T17:17:28.747Z",
  "pubdate": "2026-09-03T17:17:28.747Z",
  "executiveSummary": "The Migrate Guru – Site Migration & Cloning plugin, in versions 6.65 and below, contains a critical vulnerability that allows unauthenticated attackers to perform a Denial of Service (DoS) attack against the hosting environment.\nThis vulnerability stems from improper handling of incoming requests, enabling an attacker to trigger resource exhaustion without the need for administrative credentials.\nThe primary risk implication is the degradation or complete cessation of service availability for the affected WordPress installation. Because the attack requires no authentication or special privileges, any remote user with network access to the target site can initiate the exploit.\nThe impact is significant, as it can disrupt site operations and migration workflows, potentially causing data loss or service downtime. Organizations relying on this plugin for site management should treat this as a high-priority risk and implement restrictive access controls or perform immediate updates if available.",
  "technicalDetails": "The vulnerability resides within the request processing logic of the Migrate Guru plugin. Investigation into versions <= 6.65 indicates that the plugin fails to adequately sanitize or validate specific input parameters during the migration initialization or polling phases.\nThe root cause is an improper resource management flaw that allows an attacker to send a specially crafted request to an exposed endpoint used by the plugin. When processed, this request consumes disproportionate server resources—such as CPU cycles or memory—or initiates persistent loops that overwhelm the server's execution environment.\nThe attack flow begins with an unauthenticated user identifying the target endpoint associated with the Migrate Guru plugin's migration process. By submitting a malicious payload, the attacker forces the application to execute a resource-intensive operation repeatedly. Since the plugin does not enforce authentication checks or rate limiting for these specific internal calls, the server is forced to handle the heavy load induced by the attacker.\nBecause the vulnerability can be triggered remotely without administrative privileges, it presents a significant threat to the availability of the hosting server. The payload behavior typically involves triggering a blocking process or an infinite execution state that consumes the maximum PHP execution time, effectively locking the thread for the duration of the attack. If performed concurrently or distributed across multiple requests, this leads to a full service outage.\nThe vulnerable component is identified as part of the plugin's core migration functionality, which is active regardless of whether an active migration is currently in progress. The network exposure is broad, as any client capable of reaching the WordPress installation can interact with the affected endpoint. Post-exploitation, the server may remain unresponsive for an extended period, requiring manual intervention or administrative service restarts to restore standard operations."
}
CVE-2026-84778: Migrate Guru Unauthenticated DoS Vulnerability (HIGH Severity, CVSS: 7.5) - Sceawere