CVE-2026-95587: WordPress Hostinger Migrator plugin <= 1.0 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/hostinger-migratorto a version that resolves this vulnerability.Fixed in 1.1.0
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. It is remotely reachable with low attack complexity and does not require user interaction.
What is the likely security impact?
The supplied severity vector indicates high confidentiality impact, with no indicated integrity or availability impact. The scope is unchanged.
Which installations are identified as affected?
Hostinger Migrator versions 1.0 and earlier are identified as affected. The provided information does not state whether the plugin is enabled by default or provide a fixed version.