CVE-2025-11427

MEDIUM

WP Migrate Lite <= 2.7.6 - Unauthenticated Blind SSRF via wpmdb_flush

Title source: llm
STIX 2.1

Description

The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.7.6 via the wpmdb_flush AJAX action. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to obtain information about internal services.

Scores

CVSS v3 5.8
EPSS 0.0040
EPSS Percentile 32.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
wpengine/WP Migrate Lite – Migration Made Easy < 2.7.6
wpengine/WP Migrate Lite – WordPress Migration Made Easy < 2.7.6
Published Nov 18, 2025
Tracked Since Feb 18, 2026