Impact
The Prime Mover WordPress plugin, versions prior to 2.2.1, contains a path traversal flaw that allows a site administrator who is authenticated to delete an arbitrary directory on the server. By supplying a crafted wprime-config.json file when importing a WPRIME/TAR archive, the attacker can manipulate the tar_root_folder value to bypass the plugin’s validation logic. The deletion is performed through the primeMoverDoDelete() routine, potentially removing critical WordPress directories such as wp-admin and rendering the site inoperable.
Affected Systems
Codexonics Prime Mover plugins installed on WordPress sites that are running a version older than 2.2.1 are vulnerable, regardless of the theme or other plugins used. All affected sites with that plugin version may be impacted.
Risk and Exploitability
The flaw has a CVSS score of 7, indicating a medium to high severity level. It requires the attacker to be an authenticated administrator, which is inferred from the description; many sites expose the WordPress admin interface or use weak credentials, making initial compromise more likely. Once authenticated, an attacker can upload a malicious archive and trigger the deletion with little effort. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the potential to permanently damage or destroy site content means that exploitation could cause significant downtime, loss of revenue, or complete site loss.
OpenCVE Enrichment