HomeDefault status
affected
Any version
affected
Description
The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions due to a hardcoded secret.
Problem types
CWE-269 Improper Privilege Management
Product status
Any version
Credits
Khaled Alenazi (Nxploited)
WPScan
References
wpscan.com/...rability/d12332ec-1d0c-4ff5-94e0-7c4470bdb79c/