
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32515 is a Missing Authorization (Broken Access Control) vulnerability in the WordPress "Miraculous" theme developed by kamleshyadav. It allows unauthenticated remote attackers to exploit incorrectly configured access control security levels, potentially causing a high availability impact. All versions of the theme prior to 2.1.2 are affected. The vulnerability was reported on January 22, 2026, by researcher Trương Hữu Phúc (truonghuuphuc) and published on March 20–25, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning one or more functions within the Miraculous WordPress theme fail to perform adequate authorization, authentication, or nonce token checks before executing privileged actions (Patchstack). The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The vulnerability is categorized under OWASP Top 10 A1: Broken Access Control. No public proof-of-concept code has been identified at this time.
Successful exploitation results in a high availability impact, as indicated by the CVSS vector (C:N/I:N/A:H), meaning attackers can disrupt the availability of affected WordPress sites without gaining access to confidential data or modifying content (Patchstack). The vulnerability is considered suitable for mass-exploit campaigns targeting thousands of WordPress websites simultaneously, regardless of site size or traffic. Confidentiality and integrity impacts are assessed as none based on the current CVSS scoring.
The vulnerability requires no privileges or user interaction, making it accessible to unauthenticated attackers over the network with low complexity (Patchstack). Patchstack has flagged it as high priority and notes that vulnerabilities of this class are commonly used in mass-exploit campaigns. The EPSS score is approximately 0.017% (0.000170), indicating a currently low but non-negligible probability of exploitation in the near term. No confirmed in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been identified for this CVE.
The vendor has released version 2.1.2 of the Miraculous WordPress theme, which resolves the vulnerability; updating to this version or later is the recommended remediation (Patchstack). For site owners unable to update immediately, Patchstack has issued a virtual patch (mitigation rule) to block exploitation attempts until the theme is updated. Site administrators should also review their WordPress theme and plugin inventory for other access control issues and consider enabling a web application firewall.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."