Zip Slip Vulnerability in Prime Mover WordPress Plugin
The Prime Mover WordPress plugin before version 2.2.1 is vulnerable to Zip Slip, allowing authenticated administrators to perform arbitrary file writes via path traversal during ZIP archive extraction.
CVE search metadata
CVE search record: CVE-2026-101888. Severity: high. CVSS: 7.2. KEV: no. Product: Prime Mover (< 2.2.1). Brief: Zip Slip Vulnerability in Prime Mover WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-prime-mover-zip-slip/
The Prime Mover plugin for WordPress, prior to version 2.2.1, contains a Zip Slip vulnerability residing in its migration ZIP import functionality. This vulnerability occurs because the plugin fails to properly sanitize the filenames of entries within uploaded ZIP archives during the extraction process. Specifically, the functions computeExtractionParameters() and resumableZipExtractor(), located within utilities/PrimeMoverSystemCheckUtilities.php, process entry names containing path traversal sequences. An authenticated administrator can craft a malicious ZIP archive containing entries with relative path components (e.g., ../) to force the application to extract files outside of the intended directory. This permits an attacker to overwrite critical system or application files, potentially leading to remote code execution if the environment is configured to interpret or execute the attacker-controlled files.
Impact
The vulnerability allows for arbitrary file write and potential remote code execution on the affected WordPress site. Successful exploitation requires an authenticated administrative account, limiting the initial vector to users with existing high-privilege access. If exploited, an attacker could gain full control over the web application environment by overwriting configuration files or injecting web shells into reachable directories.
Recommendation
Update the Prime Mover plugin to version 2.2.1 or later to remediate the Zip Slip path traversal vulnerability (CVE-2026-101888).
Reference
Mitigations
Update Prime Mover plugin to version 2.2.1 or later.
CVE-2026-101888