Executive brief
WP Migrate Lite is a popular WordPress plugin used to move website databases and files between different environments. A security flaw allows an attacker to trick a website administrator into performing unintended actions, such as changing settings or initiating migrations, by clicking a malicious link. While this requires the administrator to be logged in and interact with the link, it could lead to unauthorized changes to the site's configuration or data management processes.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Migrate Lite plugin for WordPress due to missing or insufficient nonce validation on sensitive actions. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a logged-in administrator into executing it via social engineering (e.g., a phishing link). Successful exploitation allows the attacker to perform unauthorized actions on behalf of the administrator, potentially impacting the availability or integrity of the site's migration settings. The issue is resolved in version 2.7.9.
Affected products
- Delicious Brains WP Migrate Lite <= 2.7.8
Timeline
- 2026-02-11: other: Reported by Nguyen Ba Khanh
- 2026-06-10: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date