๐Ÿ” CVE Alert

CVE-2026-101890

MEDIUM 5.4

Prime Mover < 2.2.1 Stored XSS via Package Metadata

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory so that the malicious value renders unescaped in the column_site_title() method of PrimeMoverBackupMenuListTable.php, triggering script execution in an administrator's browser when they view the Prime Mover Packages list table without needing to restore the package.

CWE CWE-79
Vendor codexonics
Product prime mover
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for codexonics prime mover

Be the first to know when new medium vulnerabilities affecting codexonics prime mover are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Codexonics / Prime Mover
0 < 2.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordpress.org: https://wordpress.org/plugins/prime-mover/#developers vulncheck.com: https://www.vulncheck.com/advisories/prime-mover-stored-xss-via-package-metadata

Credits

Sarvar Eshboyev