Impact
The 1 Click Migration & Backup plugin contains a missing capability check on the start_restore function in all versions up to 2.2, allowing an authenticated user with Subscriber role or higher to upload arbitrary files to the server. This flaw is a static file upload vulnerability (CWE‑434) that can enable remote code execution if the attacker places executable content.
Affected Systems
Any WordPress site that has installed the 1 Click Migration & Backup plugin version 2.2 or earlier. The plugin is distributed by 1clickmigration and is used by WordPress site administrators for migration and backup tasks.
Risk and Exploitability
The vulnerability scores a high CVSS of 8.8 and has an EPSS score of 1 %, indicating a low but non‑zero likelihood of exploitation in the wild. Because it is triggered by a role that is commonly assigned to content editors or subscribers, a legitimate user with such permissions could easily exploit the flaw if the plugin is not patched. The flaw is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
EUVD