CVE WATCH / VULNERABILITY DETAIL

CVE-2026-101890

MEDIUMCVSS 5.4NVD feed

Published 1 October 2026 · tracked since 2 October 2026

Description

The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-expo

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-101890 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-101890

MEDIUMCVSS 5.4NVD feed

Published 1 October 2026 · tracked since 2 October 2026

Description

The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-expo

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]