Impact
The Miraculous WordPress theme contains a missing authorization flaw that permits an attacker to delete content arbitrarily. The weakness, classified as CWE-862, allows a user with the wrong permissions to exploit incorrect access control settings and remove posts, pages, or other content from the site. This can lead to loss of data, interruption of services, and potential reputational damage for site owners.
Affected Systems
All instances of the Miraculous theme by kamleshyadav that are version 2.0.8 and earlier are affected. Users of this theme should verify the installed version and compare it against the latest available release.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact and medium severity. The EPSS score below 1% suggests that exploitation attempts are currently rare, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires access to the WordPress backend with sufficient privileges to edit content, so the attack vector is likely limited to authenticated users with misconfigured permissions. An attacker could therefore leverage any existing author or administrator account that lacks proper role segregation.
OpenCVE Enrichment