Record summary

CVE-2024-13609 has a selected CVSS score of 5.9 (medium); EIP currently links 1 Nuclei template.

Description

The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the class-ocm-backup.php. This makes it possible for unauthenticated attackers to extract sensitive data including usernames and their respective password hashes during a short window of time in which the backup is in process.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 31, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 18, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

1 Click Migration & Backup: Free WordPress Migration Plugin with Zero Downtime & Easy Clone

Browse 1clickmigration / 1 Click Migration & Backup: Free WordPress Migration Plugin with Zero Downtime & Easy Clone

Default status: unaffected

CVE ListThrough 2.2affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress 1 Click Migration Plugin < 2.3 - Information ExposureCVSS 5.9

The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the class-ocm-backup.php. This makes it possible for unauthenticated attackers to extract sensitive data including usernames and their respective password hashes during a short window of time in which the backup is in process.

Impact

Unauthenticated attackers can retrieve sensitive data including usernames and password hashes, risking account compromise.

Remediation

Update to the latest version of the plugin where the issue is fixed.

WeaknessesCWE-200
Authorspussycat0x
Template tagscvecve2024wpwordpresswp-plugin1clickmigrationexposurevkev
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
FOFA: body="/wp-content/plugins/1-click-migration/"

Source: ProjectDiscovery

References

4