CVE-2026-101889 - Prime Mover < 2.2.1 Path Traversal via wprime-config.json
CVE ID :CVE-2026-101889
Published : Oct. 1, 2026, 4:20 p.m. | 52 minutes ago
Description :The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation in computeExtractVariables() and validateImportedSiteVsPackage() to cause primeMoverDoDelete() to remove directories outside the intended extraction path, potentially deleting critical WordPress directories such as wp-admin and rendering the site inoperable.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 1, 2026, 4:20 p.m. | 52 minutes ago
Description :The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation in computeExtractVariables() and validateImportedSiteVsPackage() to cause primeMoverDoDelete() to remove directories outside the intended extraction path, potentially deleting critical WordPress directories such as wp-admin and rendering the site inoperable.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...