CVE WATCH / VULNERABILITY DETAIL
CVE-2026-101890
MEDIUMCVSS 5.4NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-expo
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-103921 HIGH 7.4
- CVE-2026-101888 HIGH 7.2
- CVE-2026-101889 MEDIUM 6.5
- CVE-2026-94620
- CVE-2026-46729 HIGH 7.5
- CVE-2026-47360 HIGH 7.5
- CVE-2026-42356 LOW 3.7
- CVE-2026-42528 MEDIUM 4.3
- CVE-2026-103690 MEDIUM 6.3
- CVE-2026-97284 HIGH 8.8