WP Engine WP Migrate Plugin Unauthenticated PHP Object Injection Vulnerability

Vulnerability

A deserialization vulnerability allowing PHP object injection has been identified in the WP Engine WP Migrate plugin, affecting versions through 2.6.10. This vulnerability could be exploited to execute arbitrary code, inject SQL, traverse directories, cause a denial of service, and more, if a suitable object injection chain is available.

Impact

Exploitation of this vulnerability could lead to unauthorized PHP object injection, with the potential for executing arbitrary code, injecting malicious SQL, traversing directories in an unauthorized manner, causing a denial of service, and other impacts, depending on the exploitation chain used.

Remediation

Users of the WP Migrate plugin should update to version 2.6.11 or later. Patchstack users can enable auto-updates for vulnerable plugins.

Added: May 15, 2026, 9:35 AM
Updated: May 15, 2026, 9:35 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.8
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.