WordPress 的 Prime Mover 插件在 2.2.1 版本之前存在路径遍历漏洞,允许经过身份验证的管理员通过导入一个精心构造的 WPRIME/TAR 包(其中 wprime-config.json 文件中的 tar_root_folder 值被篡改)来删除任意目录。攻击者可利用 computeExtractVariables() 和 validateImportedSiteVsPackage() 函数中不足的路径验证机制,使 primeMoverDoDelete() 函数删除预期解压路径之外的目录,从
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Codexonics | Prime Mover | 0 ~ 2.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101888 | 7.2 HIGH | Prime Mover < 2.2.1 Zip Slip Path Traversal File Write |
| CVE-2026-101890 | 5.4 MEDIUM | Prime Mover < 2.2.1 Stored XSS via Package Metadata |
No comments yet