Back

HIGH

Prime Mover < 2.2.1 Path Traversal via wprime-config.json

Published Oct 1, 2026

Description

The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation in computeExtractVariables() and validateImportedSiteVsPackage() to cause primeMoverDoDelete() to remove directories outside the intended extraction path, potentially deleting critical WordPress directories such as wp-admin and rendering the site inoperable.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Oct 1, 2026
Updated Oct 1, 2026
Reserved Sep 28, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Deferred
Modified Oct 2, 2026
Red Hat
Severity n/a
Public date n/a