CPE
The Prime Mover WordPress plugin before version 2.2.1 is vulnerable to Zip Slip, allowing authenticated administrators to perform arbitrary file writes via path traversal during ZIP archive extraction.