CVE-2026-101889
Received Received - Intake

Path Traversal in Prime Mover WordPress Plugin

Vulnerability report for CVE-2026-101889, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation in computeExtractVariables() and validateImportedSiteVsPackage() to cause primeMoverDoDelete() to remove directories outside the intended extraction path, potentially deleting critical WordPress directories such as wp-admin and rendering the site inoperable.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
prime_mover prime_mover to 2.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in the Prime Mover WordPress plugin before version 2.2.1. Authenticated administrators can exploit it by importing a specially crafted package with manipulated tar_root_folder values in wprime-config.json. The plugin's insufficient path validation allows the primeMoverDoDelete() function to delete directories outside the intended extraction path, potentially including critical WordPress directories like wp-admin.

Detection Guidance

Check for the Prime Mover plugin version. If it is below 2.2.1, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin directory for version details.

Impact Analysis

An attacker with admin access could delete arbitrary directories on your WordPress site, including critical folders like wp-admin. This could make your website inoperable, cause data loss, or disrupt site functionality. The vulnerability requires administrative privileges to exploit.

Compliance Impact

This vulnerability could lead to unauthorized deletion of critical WordPress directories, potentially causing data loss or system unavailability. For GDPR, this may result in violations of integrity and availability requirements under Article 32. For HIPAA, it could compromise the integrity of PHI if backup or migration processes are disrupted.

Mitigation Strategies

Update the Prime Mover plugin to version 2.2.1 or later immediately. Remove administrative access for unnecessary users and monitor for suspicious activity involving file deletions or imports.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101889. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart