WordPress Miraculous Elementor Plugin Authentication Bypass Vulnerability

Vulnerability

A vulnerability allowing authentication bypass has been identified in the WordPress Miraculous Elementor plugin, specifically in versions through 2.0.7. This issue arises from authentication abuse, which could enable unauthorized users to perform actions reserved for higher-privileged users, potentially leading to admin access on the website.

Impact

Exploitation of this vulnerability could allow a malicious actor to gain administrative access to the affected WordPress site.

Remediation

Users of the WordPress Miraculous Elementor plugin should update to version 2.0.8 or later. Patchstack users can enable auto-update for vulnerable plugins.

Added: Feb 20, 2026, 5:16 PM
Updated: Feb 20, 2026, 5:16 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
3.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.