Filtered by vendor Wpengine Subscriptions
Filtered by product Wp Migrate Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-11427 2 Wordpress, Wpengine 2 Wordpress, Wp Migrate 2025-11-19 5.8 Medium
The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.7.6 via the wpmdb_flush AJAX action. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to obtain information about internal services.
CVE-2024-30225 1 Wpengine 1 Wp Migrate 2024-11-21 10 Critical
Deserialization of Untrusted Data vulnerability in WPENGINE, INC. WP Migrate.This issue affects WP Migrate: from n/a through 2.6.10.