CVE · Medium

CVE-2025-11427 — WP Migrate Lite – Migration Made Easy [wp-migrate-db] < 2.7.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11427 WP Migrate Lite – Migration Made Easy [wp-migrate-db] < 2.7.7 Server-Side Request Forgery (SSRF) Medium 5.8 < 2.7.7 2.7.7 2025-11-17

CVE-2025-11427

The WP Migrate Lite plugin for WordPress has a security flaw in versions 2.7.6 and earlier, allowing unauthorized users to secretly trigger external website interactions through its wpmdb_flush AJAX function. This vulnerability enables attackers to gather details about the web application's underlying infrastructure without needing authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.