VYPR

Prime Mover

by WordPress

CVEs (3)

  • CVE-2026-101888HigOct 1, 2026
    risk 0.47cvss 7.2epss —

    The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with…

  • CVE-2026-101889MedOct 1, 2026
    risk 0.42cvss 6.5epss —

    The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers…

  • CVE-2026-101890MedOct 1, 2026
    risk 0.35cvss 5.4epss —

    The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under…