1 Click WordPress Migration Plugin Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability allowing sensitive information exposure has been identified in the 1 Click WordPress Migration Plugin, in all versions through 2.2. The issue resides in the class-ocm-backup.php file, where unauthenticated attackers can extract sensitive data, including usernames and password hashes, during the backup process.

Impact

Exploitation of this vulnerability allows for the unauthorized extraction of sensitive information, specifically usernames and their password hashes, during the backup process.

Reproduction

The vulnerability can be reproduced by initiating a backup process using the affected WordPress migration plugin. During this process, sensitive information such as usernames and password hashes can be extracted.

Remediation

No known patch is available. It is recommended to uninstall the affected plugin and consider a replacement.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.