Zip Slip Path Traversal Vulnerability in Prime Mover Plugin for WordPress
CVE-2026-101888

8.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 October 2026

What is CVE-2026-101888?

The Prime Mover plugin for WordPress versions prior to 2.2.1 is vulnerable to a Zip Slip path traversal issue. This vulnerability allows authenticated administrators to extract data into unintended directories during ZIP import operations. By exploiting specially crafted ZIP file entry names, attackers can manipulate the plugin's file extraction process to write malicious files to arbitrary locations on the server. If these files are subsequently executed by the web environment, it may lead to remote code execution. This flaw underscores the importance of secure file handling practices within the WordPress ecosystem.

Affected Version(s)

Prime Mover 0 < 2.2.1

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sarvar Eshboyev
.