Answer in brief
CVE-2026-101888 records a High severity (CVSS 8.6) vulnerability in Prime Mover < 2.2.1 Zip Slip Path Traversal File Write. The current sources do not mark it as known exploited. The current feed maps Codexonics/Prime Mover (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.6. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Codexonics/Prime Mover (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Codexonics/Prime Movergeneric | >=0 <2.2.1 | 2.2.1 |
Published upstream
Oct 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 1, 2026
The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by computeExtractionParameters() and resumableZipExtractor() in utilities/PrimeMoverSystemCheckUtilities.php to write attacker-controlled content to arbitrary filesystem locations, potentially achieving remote code execution if the written files are interpreted by the web environment.
Quoted source text, attributed separately from HOL analysis.