Sceawere
Vulnerability Detail
CVE-2026-95587UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Access in Hostinger Migrator
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- Hostinger
- Product
- Hostinger Migrator
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-30T13:17:28.720Z",
"pubdate": "2026-09-30T13:17:28.720Z",
"executiveSummary": "The Hostinger Migrator plugin, specifically versions 1.0 and below, contains a critical broken access control vulnerability. This security flaw allows unauthenticated remote attackers to perform unauthorized actions by bypassing standard authentication checks within the plugin's ecosystem.\nThe vulnerability originates from a failure to implement proper authorization controls on sensitive administrative or migration-related endpoints. Because the plugin does not verify the session or privilege level of the requester, an adversary can invoke restricted functionality without credentials.\nThe impact of this vulnerability is significant, as it grants attackers the ability to interact with the plugin’s core operations. Depending on the specific implementation of the vulnerable endpoints, this could facilitate unauthorized data access, manipulation of migration processes, or potential configuration changes.\nThe risk is categorized as high due to the lack of required authentication, which lowers the barrier for exploitation significantly. Any remote attacker with network access to the target WordPress installation can leverage this flaw. Organizations currently utilizing versions 1.0 or earlier of Hostinger Migrator are at risk of unauthorized system manipulation and data exposure. Immediate remediation is required to prevent exploitation by malicious actors.",
"technicalDetails": "The vulnerability is identified as a Broken Access Control issue within the Hostinger Migrator plugin, versions 1.0 and below. At its core, the flaw exists because the plugin fails to enforce proper access control checks on its exposed action handlers or API endpoints. In the WordPress ecosystem, such endpoints are often registered via 'wp_ajax_' or 'wp_ajax_nopriv_' hooks. If a developer inadvertently registers a sensitive function without appropriate permission checks, such as 'current_user_can()', the functionality becomes globally accessible to any visitor, regardless of their authorization status.\nThe attack flow begins when an attacker identifies the registered administrative action names within the plugin's code. Once identified, the attacker crafts a malicious HTTP POST or GET request directed at the 'wp-admin/admin-ajax.php' endpoint. Because the underlying code lacks a conditional gatekeeper to verify if the request originator is an administrator, the server processes the request as if it were a legitimate command.\nThe root cause is the improper handling of requests in the plugin’s request-processing logic. The implementation fails to validate the security nonce or the user's role before executing privileged operations. Consequently, the plugin implicitly trusts input coming from the network interface. This bypasses the typical security perimeter of the WordPress dashboard, essentially exposing backend migration functionality to the public web.\nAn attacker can exploit this by sending requests specifically formatted to interact with the migration process. Post-exploitation impact could include the unauthorized retrieval of site configuration details, migration logs, or the manipulation of migration parameters that may lead to further system compromise or data leakage. The absence of authentication and privilege requirements means the exploit can be automated, allowing attackers to scan for vulnerable instances of the plugin and execute the attack sequence programmatically. There is no requirement for social engineering, as the vulnerability is purely a result of insecure software design and insufficient input/authorization validation at the plugin level."
}