{"id":"CVE-2026-101889","title":"The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder…","summary":"The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-22"],"vendor":"Codexonics","product":"Prime Mover","affected":["prime_mover < 2.2.1"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T17:17:17.613","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101889","references":[{"url":"https://wordpress.org/plugins/prime-mover/#developers","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/prime-mover-path-traversal-via-wprime-config-json","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-01T16:34:04.729612Z"},"ingestedAt":"2026-10-01T18:55:42.358Z","slug":"CVE-2026-101889","body":"## Overview\n\nThe Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation in computeExtractVariables() and validateImportedSiteVsPackage() to cause primeMoverDoDelete() to remove directories outside the intended extraction path, potentially deleting critical WordPress directories such as wp-admin and rendering the site inoperable.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}