๐Ÿ” CVE Alert

CVE-2026-101889

MEDIUM 6.5

Prime Mover < 2.2.1 Path Traversal via wprime-config.json

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation in computeExtractVariables() and validateImportedSiteVsPackage() to cause primeMoverDoDelete() to remove directories outside the intended extraction path, potentially deleting critical WordPress directories such as wp-admin and rendering the site inoperable.

CWE CWE-22
Vendor codexonics
Product prime mover
Published Oct 1, 2026
Last Updated Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for codexonics prime mover

Be the first to know when new medium vulnerabilities affecting codexonics prime mover are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High

Affected Versions

Codexonics / Prime Mover
0 < 2.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordpress.org: https://wordpress.org/plugins/prime-mover/#developers vulncheck.com: https://www.vulncheck.com/advisories/prime-mover-path-traversal-via-wprime-config-json

Credits

Sarvar Eshboyev