Impact
The vulnerability is an incorrect privilege assignment flaw in the Miraculous Core Plugin version 2.0.7 or earlier. When exploited, an attacker can elevate privileges and gain higher-than‑intended permissions within the WordPress site. This weakness is categorized as CWE-266, which involves improper authorization processes.
Affected Systems
The affected product is the Miraculous Core Plugin developed by Kamleshyadav. All versions from the initial release through 2.0.7 are vulnerable; any site running this plugin on those versions is at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, and the EPSS score of less than 1% shows that while exploitation potential is low at the moment, the flaw remains a high‑impact threat. The vulnerability is not listed in the CISA KEV catalog. The attack does not explicitly state a vector, but the likely path involves interaction with plugin‑provided functionality that improperly assigns capabilities to users. Given the plugin’s role in site management, an attacker with access to the plugin’s configuration could potentially exploit the flaw.
OpenCVE Enrichment
EUVD