Blind Server-Side Request Forgery Vulnerability in WP Migrate Lite Plugin
CVE-2025-11427
5.8MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 November 2025
What is CVE-2025-11427?
The WP Migrate Lite plugin for WordPress is subject to a critical vulnerability that allows unauthenticated attackers to exploit the wpmdb_flush AJAX action. This weakness enables them to make unauthorized web requests to arbitrary locations, potentially exposing sensitive internal services. Versions up to and including 2.7.6 are affected, highlighting the importance of updating and securing your WordPress installations.
Affected Version(s)
WP Migrate Lite β Migration Made Easy 0 <= 2.7.6