CVE-2026-101890
Received Received - Intake

Stored XSS in Prime Mover WordPress Plugin

Vulnerability report for CVE-2026-101890, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory so that the malicious value renders unescaped in the column_site_title() method of PrimeMoverBackupMenuListTable.php, triggering script execution in an administrator's browser when they view the Prime Mover Packages list table without needing to restore the package.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
prime_mover plugin to 2.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in the Prime Mover WordPress plugin before version 2.2.1. Attackers can inject malicious JavaScript by adding an unescaped site_title value to a package's footprint.json file. When an administrator views the Prime Mover Packages list table, the malicious script executes in their browser without needing to restore the package.

Detection Guidance

Check for unescaped site_title values in footprint.json files within the prime-mover-export-files directory. Review the Prime Mover Packages list table in WordPress admin for suspicious JavaScript execution. Look for packages with malicious payloads in the export directory.

Impact Analysis

If you are a WordPress administrator using the Prime Mover plugin before version 2.2.1, an attacker could steal your session cookies, perform actions on your behalf, or redirect you to malicious websites. This could lead to unauthorized access to your WordPress site or compromise of sensitive data.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate GDPR's data protection requirements or HIPAA's security rules. Organizations could face fines or penalties if this vulnerability results in exposure of personal or health data.

Mitigation Strategies

Update the Prime Mover plugin to version 2.2.1 or later. Remove any untrusted packages from the prime-mover-export-files directory. Scan for and remove any footprint.json files containing unescaped site_title values with malicious scripts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101890. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart