Description
The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory so that the malicious value renders unescaped in the column_site_title() method of PrimeMoverBackupMenuListTable.php, triggering script execution in an administrator's browser when they view the Prime Mover Packages list table without needing to restore the package.
Published: 2026-10-01
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross-site Scripting (XSS)
Action: Patch
AI Analysis

Impact

The Prime Mover plugin for WordPress versions prior to 2.2.1 contains a stored XSS flaw that allows an attacker to import a malicious package with an unescaped site_title value in its footprint.json file. When an administrator opens the Prime Mover Packages list, the value is rendered without sanitization in the column_site_title() method, causing the embedded JavaScript to execute in the administrator’s browser. This flaw can lead to credential theft, session hijacking, or defacement within the context of the victim’s WordPress site. The vulnerability is an instance of CWE‑79.

Affected Systems

The vulnerability affects the Codexonics Prime Mover WordPress plugin, specifically all versions earlier than 2.2.1. The flaw exists in the PrimeMoverBackupMenuListTable.php component that processes package metadata stored under the prime‑mover-export‑files directory.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalogue. Exploitation likely requires the attacker to be able to upload or place a crafted package file in the plugin’s export directory, which typically necessitates either a vulnerable attachment upload process or compromised credentials. Once the malicious package is introduced, anyone with administrator privileges who views the Packages list will be exposed. While the impact is limited to the administrator’s session, the availability of JavaScript execution in that context makes the flaw exploitable and warrants prompt mitigation.

Generated by OpenCVE AI on October 1, 2026 at 17:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Prime Mover plugin to version 2.2.1 or later. This version removes the vulnerability by properly escaping the site_title value.
  • Delete any existing packages located in the prime‑mover-export‑files directory that may contain malicious content.
  • Restrict package upload permissions so that only trusted administrators can upload packages, and validate or sanitize uploaded metadata before it is stored.

Generated by OpenCVE AI on October 1, 2026 at 17:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory so that the malicious value renders unescaped in the column_site_title() method of PrimeMoverBackupMenuListTable.php, triggering script execution in an administrator's browser when they view the Prime Mover Packages list table without needing to restore the package.
Title Prime Mover < 2.2.1 Stored XSS via Package Metadata
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T18:07:51.118Z

Reserved: 2026-09-28T15:44:45.390Z

Link: CVE-2026-101890

cve-icon Vulnrichment

Updated: 2026-10-01T18:07:46.107Z

cve-icon NVD

Status : Received

Published: 2026-10-01T17:17:17.767

Modified: 2026-10-01T19:17:16.863

Link: CVE-2026-101890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T17:45:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')