{"id":"CVE-2026-101890","title":"The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file","summary":"The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. A…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"Codexonics","product":"Prime Mover","affected":["prime_mover < 2.2.1"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T19:17:16.863","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101890","references":[{"url":"https://wordpress.org/plugins/prime-mover/#developers","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/prime-mover-stored-xss-via-package-metadata","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-01T18:07:43.250398Z"},"ingestedAt":"2026-10-01T18:55:42.358Z","slug":"CVE-2026-101890","body":"## Overview\n\nThe Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory so that the malicious value renders unescaped in the column_site_title() method of PrimeMoverBackupMenuListTable.php, triggering script execution in an administrator's browser when they view the Prime Mover Packages list table without needing to restore the package.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}