CVE-2024-13609
1 Click WordPress Migration Plugin – 100% FREE for a limited time <= 2.2 - Unauthenticated Sensitive Information Exposure via Database Backup in class-ocm-backup.php
Record summary
CVE-2024-13609 has a selected CVSS score of 5.9 (medium); EIP currently links 1 Nuclei template.
Description
The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the class-ocm-backup.php. This makes it possible for unauthenticated attackers to extract sensitive data including usernames and their respective password hashes during a short window of time in which the backup is in process.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 31, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 18, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
1 Click Migration & Backup: Free WordPress Migration Plugin with Zero Downtime & Easy CloneBrowse 1clickmigration / 1 Click Migration & Backup: Free WordPress Migration Plugin with Zero Downtime & Easy CloneDefault status: unaffected | CVE List | Through 2.2 | affected |
1_click_migrationBrowse 1clickmigration / 1_click_migration | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress 1 Click Migration Plugin < 2.3 - Information ExposureCVSS 5.9
The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the class-ocm-backup.php. This makes it possible for unauthenticated attackers to extract sensitive data including usernames and their respective password hashes during a short window of time in which the backup is in process.
Impact
Unauthenticated attackers can retrieve sensitive data including usernames and password hashes, risking account compromise.
Remediation
Update to the latest version of the plugin where the issue is fixed.
Source: ProjectDiscovery