Description
Authorization Bypass Through User-Controlled Key vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Miraculous Core Plugin: from n/a through < 2.0.9.
Published: 2025-11-06
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Miraculous Core Plugin contains an Authorization Bypass Through User‑Controlled Key flaw, classified as CWE‑639. It allows an attacker to manipulate object references that are not validated, leading to unauthorized access to privileged data or actions. The primary impact is the potential to read, modify, or delete sensitive information controlled by the plugin, effectively elevating privileges without proper authentication. Based on the description, the likely attack vector is through the WordPress web interface, where an attacker can alter request parameters or URLs to reference objects they should not access. Risk and exploitability: The CVSS score of 9.8 places this issue in the Critical severity range. The EPSS score of less than 1% indicates a low estimated likelihood of exploitation in the general population, yet the absence of a KEV listing means that environments using the vulnerable plugin remain high‑value targets. The IDOR flaw can be exploited remotely by any authenticated or unauthenticated user with sufficient knowledge of the plugin’s endpoints.

Affected Systems

The vulnerability affects any WordPress installation that has the Miraculous Core Plugin by kamleshyadav installed in a version earlier than 2.0.9. All releases from the initial version through < 2.0.9 are susceptible. Administrators who have not upgraded to the patched version are at risk.

Risk and Exploitability

The combination of a critical CVSS score, even with a low EPSS, underscores the seriousness of this vulnerability. An attacker exploiting the improper access control can compromise the confidentiality, integrity, or availability of content on a WordPress site. The lack of a KEV listing does not lessen the threat, as the vulnerability remains widely exposed and can be leveraged remotely wherever the vulnerable plugin is present.

Generated by OpenCVE AI on April 29, 2026 at 16:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Miraculous Core Plugin to version 2.0.9 or later.
  • Disable or delete the plugin if it is not required for site functionality.
  • Restrict access to the plugin’s administrative UI by applying role‑based permissions or IP address whitelisting.

Generated by OpenCVE AI on April 29, 2026 at 16:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 17 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 06 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Miraculous Core Plugin: from n/a through < 2.0.9.
Title WordPress Miraculous Core Plugin plugin < 2.0.9 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:14:15.681Z

Reserved: 2025-09-03T09:03:04.976Z

Link: CVE-2025-58627

cve-icon Vulnrichment

Updated: 2025-11-17T16:30:06.074Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:15:59.557

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-58627

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T16:30:15Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key