CVE-2026-101889: Prime Mover < 2.2.1 Path Traversal via wprime-config.json
The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tarrootfolder values in wprime-config.json. Attackers can exploit insufficient path validation in computeExtractVariables() and validateImportedSiteVsPackage() to cause primeMoverDoDelete() to remove directories outside the intended extraction path, potentially deleting critical WordPress directories such as wp-admin and rendering the site inoperable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Prime Mover WordPress pluginto a version that resolves this vulnerability.Fixed in 2.2.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated as a WordPress administrator and be able to import a crafted WPRIME/TAR package. Unauthenticated users and lower-privileged users are not identified as able to exploit it in the available information.
What is the likely impact of successful exploitation?
A successful exploit can delete arbitrary directories outside the intended package extraction path. This may remove critical WordPress directories such as wp-admin and make the site inoperable.
Which installations are affected?
Prime Mover versions earlier than 2.2.1 are affected. The issue is triggered through importing a package whose wprime-config.json contains manipulated tar_root_folder values.