← All CVEs

CVE-2025-14892

critical · 9.8

The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions due to a hardcoded secret.

9.8
CVSS
0.4%
EPSS (exploit prob.)
32nd
EPSS percentile
2026-02-12
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-14892