Skip to content
Threat Feed
high advisory

Zip Slip Vulnerability in Prime Mover WordPress Plugin

The Prime Mover WordPress plugin before version 2.2.1 is vulnerable to Zip Slip, allowing authenticated administrators to perform arbitrary file writes via path traversal during ZIP archive extraction.

CVE search metadata

CVE search record: CVE-2026-101888. Severity: high. CVSS: 7.2. KEV: no. Product: Prime Mover (< 2.2.1). Brief: Zip Slip Vulnerability in Prime Mover WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-prime-mover-zip-slip/

The Prime Mover plugin for WordPress, prior to version 2.2.1, contains a Zip Slip vulnerability residing in its migration ZIP import functionality. This vulnerability occurs because the plugin fails to properly sanitize the filenames of entries within uploaded ZIP archives during the extraction process. Specifically, the functions computeExtractionParameters() and resumableZipExtractor(), located within utilities/PrimeMoverSystemCheckUtilities.php, process entry names containing path traversal sequences. An authenticated administrator can craft a malicious ZIP archive containing entries with relative path components (e.g., ../) to force the application to extract files outside of the intended directory. This permits an attacker to overwrite critical system or application files, potentially leading to remote code execution if the environment is configured to interpret or execute the attacker-controlled files.

Impact

The vulnerability allows for arbitrary file write and potential remote code execution on the affected WordPress site. Successful exploitation requires an authenticated administrative account, limiting the initial vector to users with existing high-privilege access. If exploited, an attacker could gain full control over the web application environment by overwriting configuration files or injecting web shells into reachable directories.

Recommendation

Update the Prime Mover plugin to version 2.2.1 or later to remediate the Zip Slip path traversal vulnerability (CVE-2026-101888).

Reference

Mitigations

Update Prime Mover plugin to version 2.2.1 or later.

immediate IT Operations

CVE-2026-101888