CVE-2025-14892: Unknown Prime Listing Manager
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions due to a hardcoded secret.
Affected products
- Unknown Prime Listing Manager: up to and including 1.1
Published 2026-02-12. Last modified 2026-06-17.