Impact
The Prime Mover WordPress plugin prior to version 2.2.1 contains a Zip Slip path traversal flaw that lets authenticated administrators write files to arbitrary locations during the ZIP import migration process. By constructing ZIP entries with traversal sequences, an attacker can overwrite or create files outside the intended extraction directory, potentially placing malicious code that the web environment would execute, leading to full remote code execution.
Affected Systems
Codexonics Prime Mover plugin for WordPress versions earlier than 2.2.1 are affected. Only users with administrator privileges who can perform ZIP migration imports are at risk.
Risk and Exploitability
The vulnerability scores a CVSS of 8.6, indicating high risk. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Attackers must be authenticated as administrators; however, once access is granted, the path traversal can be exploited with little effort. Given the high severity and the potential for RCE, the risk to affected installations is substantial.
OpenCVE Enrichment