Impact
The Prime Mover plugin for WordPress versions prior to 2.2.1 contains a stored XSS flaw that allows an attacker to import a malicious package with an unescaped site_title value in its footprint.json file. When an administrator opens the Prime Mover Packages list, the value is rendered without sanitization in the column_site_title() method, causing the embedded JavaScript to execute in the administrator’s browser. This flaw can lead to credential theft, session hijacking, or defacement within the context of the victim’s WordPress site. The vulnerability is an instance of CWE‑79.
Affected Systems
The vulnerability affects the Codexonics Prime Mover WordPress plugin, specifically all versions earlier than 2.2.1. The flaw exists in the PrimeMoverBackupMenuListTable.php component that processes package metadata stored under the prime‑mover-export‑files directory.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalogue. Exploitation likely requires the attacker to be able to upload or place a crafted package file in the plugin’s export directory, which typically necessitates either a vulnerable attachment upload process or compromised credentials. Once the malicious package is introduced, anyone with administrator privileges who views the Packages list will be exposed. While the impact is limited to the administrator’s session, the availability of JavaScript execution in that context makes the flaw exploitable and warrants prompt mitigation.
OpenCVE Enrichment