PoC Index

CVE-2025-14892

CRITICAL 9.8EPSS 0.4%

The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions due to a hardcoded secret.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.37% chance of exploitation in the next 30 days, 30th percentile
Published
2026-02-12
Updated
2026-04-02

Proof-of-concept exploits (1)

References

Related