Description
The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by computeExtractionParameters() and resumableZipExtractor() in utilities/PrimeMoverSystemCheckUtilities.php to write attacker-controlled content to arbitrary filesystem locations, potentially achieving remote code execution if the written files are interpreted by the web environment.
Published: 2026-10-01
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Prime Mover WordPress plugin prior to version 2.2.1 contains a Zip Slip path traversal flaw that lets authenticated administrators write files to arbitrary locations during the ZIP import migration process. By constructing ZIP entries with traversal sequences, an attacker can overwrite or create files outside the intended extraction directory, potentially placing malicious code that the web environment would execute, leading to full remote code execution.

Affected Systems

Codexonics Prime Mover plugin for WordPress versions earlier than 2.2.1 are affected. Only users with administrator privileges who can perform ZIP migration imports are at risk.

Risk and Exploitability

The vulnerability scores a CVSS of 8.6, indicating high risk. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Attackers must be authenticated as administrators; however, once access is granted, the path traversal can be exploited with little effort. Given the high severity and the potential for RCE, the risk to affected installations is substantial.

Generated by OpenCVE AI on October 1, 2026 at 17:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest plugin update (v2.2.1 or newer).
  • Limit administrator roles or disable the ZIP import feature until a patch is available.
  • Review file permissions and ensure that the web server cannot execute uploaded files; consider changing the upload directory to a non-executable location.

Generated by OpenCVE AI on October 1, 2026 at 17:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by computeExtractionParameters() and resumableZipExtractor() in utilities/PrimeMoverSystemCheckUtilities.php to write attacker-controlled content to arbitrary filesystem locations, potentially achieving remote code execution if the written files are interpreted by the web environment.
Title Prime Mover < 2.2.1 Zip Slip Path Traversal File Write
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T18:05:00.965Z

Reserved: 2026-09-28T15:44:45.390Z

Link: CVE-2026-101888

cve-icon Vulnrichment

Updated: 2026-10-01T18:04:54.886Z

cve-icon NVD

Status : Received

Published: 2026-10-01T17:17:17.453

Modified: 2026-10-01T19:17:16.733

Link: CVE-2026-101888

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T18:00:08Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')