{"id":"CVE-2026-62104","published":"2026-09-17T14:17:15.130","lastModified":"2026-09-19T03:17:14.667","description":"Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.","cvssScore":10,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/migratico-lite/vulnerability/wordpress-migratico-lite-plugin-2-6-8-remote-code-execution-rce-vulnerability?_s_id=cve","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated attackers to execute arbitrary code on the server, leading to full control over the system.","exploitability":"Exploitation is straightforward with no authentication required, making it highly exploitable.","blast_radius":"If exploited, the impact could be severe, potentially leading to complete system compromise.","remediation":"Upgrade to Migratico Lite 2.6.9 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:56:10.708Z"}}