CVE-2026-62104: WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulnerability
Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Migratico Lite Pluginto a version that resolves this vulnerability.Fixed in 2.7.1
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated and remotely exploitable. An attacker does not need an account or user interaction to attempt exploitation.
Which installations are affected?
Migratico Lite versions 2.6.8 and earlier are affected according to the available data. The provided information does not state whether any particular WordPress configuration or feature must be enabled.
What impact could successful exploitation have?
Successful exploitation can result in remote code execution. The supplied severity vector indicates high confidentiality, integrity, and availability impact, with scope changed.