CVE WATCH / VULNERABILITY DETAIL
CVE-2026-101888
HIGHCVSS 7.2NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences pro
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-103921 HIGH 7.4
- CVE-2026-101889 MEDIUM 6.5
- CVE-2026-101890 MEDIUM 5.4
- CVE-2026-94620
- CVE-2026-46729 HIGH 7.5
- CVE-2026-47360 HIGH 7.5
- CVE-2026-42356 LOW 3.7
- CVE-2026-42528 MEDIUM 4.3
- CVE-2026-103690 MEDIUM 6.3
- CVE-2026-97284 HIGH 8.8