CVE-2025-14892 PUBLISHED

Prime Listing Manager <= 1.1 - Unauthenticated Privilege Escalation

Assigner: WPScan
Reserved: 18.12.2025 Published: 12.02.2026 Updated: 12.02.2026

The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions due to a hardcoded secret.

Product Status

Vendor Unknown
Product Prime Listing Manager
Versions Default: affected
  • affected from 0 to 1.1 (incl.)

Credits

  • Khaled Alenazi (Nxploited) finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE