Blind Server-Side Request Forgery Vulnerability in WP Migrate Lite Plugin
CVE-2025-11427

5.8MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 November 2025

What is CVE-2025-11427?

The WP Migrate Lite plugin for WordPress is subject to a critical vulnerability that allows unauthenticated attackers to exploit the wpmdb_flush AJAX action. This weakness enables them to make unauthorized web requests to arbitrary locations, potentially exposing sensitive internal services. Versions up to and including 2.7.6 are affected, highlighting the importance of updating and securing your WordPress installations.

Affected Version(s)

WP Migrate Lite – Migration Made Easy 0 <= 2.7.6

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.