CVE-2025-14892
CRITICAL 9.8EPSS 0.4%
The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions due to a hardcoded secret.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 0.37% chance of exploitation in the next 30 days, 30th percentile
- Published
- 2026-02-12
- Updated
- 2026-04-02