PT-2025-45245 · Kamleshyadav+1 · Miraculous Core Plugin+1

CVE-2025-58627

·

Published

2025-09-01

·

Updated

2025-11-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Miraculous Core Plugin versions prior to 2.0.9
Description The plugin contains an Insecure Direct Object Reference (IDOR) issue, which occurs when an application provides direct access to objects based on user-supplied input. This is caused by missing validation on a user-controlled key, allowing unauthenticated attackers to bypass access control security levels and perform unauthorized actions.
Recommendations Update the plugin to version 2.0.9 or later.

Fix

DoS

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-58627

Affected Products

Miraculous Core Plugin
Miraculouscore