Description
The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation in computeExtractVariables() and validateImportedSiteVsPackage() to cause primeMoverDoDelete() to remove directories outside the intended extraction path, potentially deleting critical WordPress directories such as wp-admin and rendering the site inoperable.
Published: 2026-10-01
Score: 7 High
EPSS: n/a
KEV: No
Impact: Directory Deletion
Action: Patch
AI Analysis

Impact

The Prime Mover WordPress plugin, versions prior to 2.2.1, contains a path traversal flaw that allows a site administrator who is authenticated to delete an arbitrary directory on the server. By supplying a crafted wprime-config.json file when importing a WPRIME/TAR archive, the attacker can manipulate the tar_root_folder value to bypass the plugin’s validation logic. The deletion is performed through the primeMoverDoDelete() routine, potentially removing critical WordPress directories such as wp-admin and rendering the site inoperable.

Affected Systems

Codexonics Prime Mover plugins installed on WordPress sites that are running a version older than 2.2.1 are vulnerable, regardless of the theme or other plugins used. All affected sites with that plugin version may be impacted.

Risk and Exploitability

The flaw has a CVSS score of 7, indicating a medium to high severity level. It requires the attacker to be an authenticated administrator, which is inferred from the description; many sites expose the WordPress admin interface or use weak credentials, making initial compromise more likely. Once authenticated, an attacker can upload a malicious archive and trigger the deletion with little effort. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the potential to permanently damage or destroy site content means that exploitation could cause significant downtime, loss of revenue, or complete site loss.

Generated by OpenCVE AI on October 1, 2026 at 17:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Prime Mover plugin to version 2.2.1 or later.
  • If an upgrade is not immediately possible, disable the WPRIME/TAR import feature or restrict it to trusted users only.
  • Restrict WordPress administrator access by enforcing strong passwords, two‑factor authentication, and IP whitelisting to limit the window of opportunity for an attacker.

Generated by OpenCVE AI on October 1, 2026 at 17:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Codexonics
Codexonics prime Mover
CPEs cpe:2.3:a:codexonics:prime_mover:*:*:*:*:*:wordpress:*:*
Vendors & Products Codexonics
Codexonics prime Mover

Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation in computeExtractVariables() and validateImportedSiteVsPackage() to cause primeMoverDoDelete() to remove directories outside the intended extraction path, potentially deleting critical WordPress directories such as wp-admin and rendering the site inoperable.
Title Prime Mover < 2.2.1 Path Traversal via wprime-config.json
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Codexonics Prime Mover
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T21:44:57.359Z

Reserved: 2026-09-28T15:44:45.390Z

Link: CVE-2026-101889

cve-icon Vulnrichment

Updated: 2026-10-01T16:34:09.987Z

cve-icon NVD

Status : Received

Published: 2026-10-01T17:17:17.613

Modified: 2026-10-01T17:17:17.613

Link: CVE-2026-101889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T17:30:10Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')