CVE WATCH / VULNERABILITY DETAIL

CVE-2026-101888

HIGHCVSS 7.2NVD feed

Published 1 October 2026 · tracked since 2 October 2026

Description

The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences pro

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-101888 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-101888

HIGHCVSS 7.2NVD feed

Published 1 October 2026 · tracked since 2 October 2026

Description

The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences pro

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]