CVE-2026-84778
Deferred Deferred - Pending Action

Unauthenticated Denial of Service in Migrate Guru

Vulnerability report for CVE-2026-84778, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: Patchstack

Description

Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration &amp; Cloning <= 6.65 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
migrate_guru migrate_guru to 6.65 (inc)
wp_migrate_guru migrate_guru to 6.65 (inc)
wp_migrate_guru migrate_guru 6.72

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated Denial of Service (DoS) vulnerability affecting Migrate Guru versions 6.65 and below. It allows remote attackers to disrupt service without any authentication or user interaction.

Detection Guidance

To detect this vulnerability, check if your Migrate Guru plugin version is 6.65 or below. If so, update to version 6.72 immediately. Monitor for unusual website hangs or unresponsiveness, which may indicate exploitation.

Impact Analysis

The vulnerability can cause service outages by overwhelming the target system, leading to downtime for websites using affected Migrate Guru versions. No data theft or modification occurs, but availability is compromised.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA. However, a Denial of Service attack could disrupt services handling sensitive data, potentially leading to violations if systems become unavailable during critical operations or if data processing is interrupted.

Mitigation Strategies

Update Migrate Guru to the latest version (6.65 or higher) to patch the vulnerability. If immediate update is not possible, consider disabling the plugin temporarily until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84778. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart