Description
Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration 1-click-migration allows Retrieve Embedded Sensitive Data.This issue affects 1 Click WordPress Migration: from n/a through <= 2.5.7.
Published: 2025-04-04
Score: 5.3 Medium
EPSS: 1.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The 1 Click WordPress Migration plugin contains an Uncleared Debug Information flaw that allows the retrieval of embedded sensitive data. The vulnerability is described as a Sensitive Data Exposure rather than a code execution or privilege escalation issue. It is classified under CWE‑1258, indicating that sensitive information is inadvertently exposed when debugging is not fully cleared. The impact is non‑destructive; the CVE description does not specify direct compromise potential beyond exposing information that could be valuable to an attacker.

Affected Systems

Targeted systems are WordPress installations that use the 1 Click WordPress Migration plugin version 2.5.7 or earlier. The vulnerability applies to all versions of the plugin listed as affected in the CNA data, from the earliest released version through the 2.5.7 release. WordPress sites hosting this plugin, regardless of the WordPress core version, are at risk until the plugin is updated to a patched release or the debug information functionality is disabled.

Risk and Exploitability

With a CVSS score of 5.3, the vulnerability is rated as moderate. The EPSS score of 1% indicates a low but non‑zero likelihood of exploitation; it is not listed in the CISA KEV catalog. The CVE description highlights a problem with uncleared debug information that exposes sensitive system data, but the data does not provide explicit details about further exploitation steps, privilege requirements, or attack paths.

Generated by OpenCVE AI on May 1, 2026 at 11:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the 1 Click WordPress Migration plugin to the latest available version (2.5.8 or newer) once a patch is released by the vendor.
  • If a fix is not yet available, immediately disable any debugging or logging features within the plugin to prevent exposure of sensitive data; this may involve editing plugin files or updating configuration settings that turn off debug output.
  • After disabling debugging, conduct a thorough audit of the site’s logs and file system to ensure no residual sensitive information remains accessible, and schedule a regular review to confirm no debug data is re‑introduced by future plugin updates.

Generated by OpenCVE AI on May 1, 2026 at 11:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9790 Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration allows Retrieve Embedded Sensitive Data. This issue affects 1 Click WordPress Migration: from n/a through 2.2.
History

Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration 1-click-migration allows Retrieve Embedded Sensitive Data.This issue affects 1 Click WordPress Migration: from n/a through <= 2.6.1. Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration 1-click-migration allows Retrieve Embedded Sensitive Data.This issue affects 1 Click WordPress Migration: from n/a through <= 2.5.7.
Title WordPress 1 Click WordPress Migration plugin <= 2.6.1 - Sensitive Data Exposure vulnerability WordPress 1 Click WordPress Migration plugin <= 2.5.7 - Sensitive Data Exposure vulnerability

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration 1-click-migration allows Retrieve Embedded Sensitive Data.This issue affects 1 Click WordPress Migration: from n/a through <= 2.5.7. Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration 1-click-migration allows Retrieve Embedded Sensitive Data.This issue affects 1 Click WordPress Migration: from n/a through <= 2.6.1.
Title WordPress 1 Click WordPress Migration plugin <= 2.5.7 - Sensitive Data Exposure vulnerability WordPress 1 Click WordPress Migration plugin <= 2.6.1 - Sensitive Data Exposure vulnerability
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration allows Retrieve Embedded Sensitive Data. This issue affects 1 Click WordPress Migration: from n/a through 2.2. Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration 1-click-migration allows Retrieve Embedded Sensitive Data.This issue affects 1 Click WordPress Migration: from n/a through <= 2.5.7.
Title WordPress 1 Click WordPress Migration Plugin <= 2.2 - Sensitive Data Exposure vulnerability WordPress 1 Click WordPress Migration plugin <= 2.5.7 - Sensitive Data Exposure vulnerability
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 08 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration allows Retrieve Embedded Sensitive Data. This issue affects 1 Click WordPress Migration: from n/a through 2.2.
Title WordPress 1 Click WordPress Migration Plugin <= 2.2 - Sensitive Data Exposure vulnerability
Weaknesses CWE-1258
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:19.936Z

Reserved: 2025-04-04T10:02:14.481Z

Link: CVE-2025-32257

cve-icon Vulnrichment

Updated: 2025-04-08T18:25:41.559Z

cve-icon NVD

Status : Deferred

Published: 2025-04-04T16:15:35.343

Modified: 2026-04-28T19:31:34.390

Link: CVE-2025-32257

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T11:15:15Z

Weaknesses