{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awp-prime-moverprime-moverwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wp-prime-mover:prime-mover:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-101888"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Prime Mover (\u003c 2.2.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Prime Mover plugin for WordPress, prior to version 2.2.1, contains a Zip Slip vulnerability residing in its migration ZIP import functionality. This vulnerability occurs because the plugin fails to properly sanitize the filenames of entries within uploaded ZIP archives during the extraction process. Specifically, the functions computeExtractionParameters() and resumableZipExtractor(), located within utilities/PrimeMoverSystemCheckUtilities.php, process entry names containing path traversal sequences. An authenticated administrator can craft a malicious ZIP archive containing entries with relative path components (e.g., ../) to force the application to extract files outside of the intended directory. This permits an attacker to overwrite critical system or application files, potentially leading to remote code execution if the environment is configured to interpret or execute the attacker-controlled files.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for arbitrary file write and potential remote code execution on the affected WordPress site. Successful exploitation requires an authenticated administrative account, limiting the initial vector to users with existing high-privilege access. If exploited, an attacker could gain full control over the web application environment by overwriting configuration files or injecting web shells into reachable directories.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Prime Mover plugin to version 2.2.1 or later to remediate the Zip Slip path traversal vulnerability (CVE-2026-101888).\u003c/p\u003e\n\u003ch2 id=\"reference\"\u003eReference\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-101888\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-101888\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T18:13:01Z","date_published":"2026-10-01T18:13:01Z","id":"https://feed.craftedsignal.io/briefs/2026-10-prime-mover-zip-slip/","summary":"The Prime Mover WordPress plugin before version 2.2.1 is vulnerable to Zip Slip, allowing authenticated administrators to perform arbitrary file writes via path traversal during ZIP archive extraction.","title":"Zip Slip Vulnerability in Prime Mover WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-prime-mover-zip-slip/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wp-Prime-Mover:prime-Mover:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}