XServer Migrator
XServer Migrator has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for XServer Migrator has a vendor fix available, so running the current release closes it.
All of these findings were reported by Dimas Maulana. XServer Migrator is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2024-33913Xserver Migrator <= 1.6.2 - Cross-Site Request Forgery to Arbitrary File Upload
Read the full analysisVulnerability Records

XServer Migrator
Author
XServer
エックスサーバー株式会社が提供するレンタルサーバーサービスの「エックスサーバー」「wpX Speed」で「WordPress簡単移行機能」をご利用いただくためのプラグインです。 本プラグインを利用すると、他社サーバーでお使いのWordPressを弊社のサーバーへ移行することができます。 利用対象 「エックスサーバー」「wpX Speed」をご契約のお客様のみ、無料でご利用いただけます。 ご利用いただく際は、各レンタルサーバーサービスの「WordPress簡単移行機能」から、WordPressのURLとログイン情報を入力してください。 サポート プラグインの使用方法は、マニュアルをご参照ください。 ▼エックスサーバー マニュアル https://www.xserver.ne.jp/manual/man_install_transfer_wp.php ▼wpX Speed マニュアル https://www.wpx.ne.jp/support/manual/man_transfer_easy.php
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C