CVE WATCH / VULNERABILITY DETAIL
CVE-2026-101889
MEDIUMCVSS 6.5NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficie
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-103921 HIGH 7.4
- CVE-2026-101888 HIGH 7.2
- CVE-2026-101890 MEDIUM 5.4
- CVE-2026-94620
- CVE-2026-46729 HIGH 7.5
- CVE-2026-47360 HIGH 7.5
- CVE-2026-42356 LOW 3.7
- CVE-2026-42528 MEDIUM 4.3
- CVE-2026-103690 MEDIUM 6.3
- CVE-2026-97284 HIGH 8.8