1 Click WordPress Migration
cpe:2.3:a:1clickmigration:1_click_migration:*:*:*:*:wordpress:*:*
- <= 2.2
A vulnerability allowing sensitive information exposure has been identified in the 1 Click WordPress Migration Plugin, in all versions through 2.2. The issue resides in the class-ocm-backup.php file, where unauthenticated attackers can extract sensitive data, including usernames and password hashes, during the backup process.
Exploitation of this vulnerability allows for the unauthorized extraction of sensitive information, specifically usernames and their password hashes, during the backup process.
The vulnerability can be reproduced by initiating a backup process using the affected WordPress migration plugin. During this process, sensitive information such as usernames and password hashes can be extracted.
No known patch is available. It is recommended to uninstall the affected plugin and consider a replacement.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.