vulnerability
WordPress Plugin: miraculouscore: CVE-2025-58627: Authorization Bypass Through User-Controlled Key
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:N/I:P/A:N) | Sep 1, 2025 | Nov 12, 2025 | Nov 12, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Sep 1, 2025
Added
Nov 12, 2025
Modified
Nov 12, 2025
Description
The miraculouscore plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 2.0.9 (exclusive) due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Solution
miraculouscore-plugin-cve-2025-58627
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.