CVE-2026-101890
- EPSS 0.16%
- Veröffentlicht 01.10.2026 16:22:08
- Zuletzt bearbeitet 02.10.2026 18:00:34
The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can ...
CVE-2026-101889
- EPSS 0.35%
- Veröffentlicht 01.10.2026 16:20:54
- Zuletzt bearbeitet 02.10.2026 18:00:34
The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wp...
CVE-2026-101888
- EPSS 0.59%
- Veröffentlicht 01.10.2026 16:19:51
- Zuletzt bearbeitet 02.10.2026 18:00:34
The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can ...
CVE-2023-6505
- EPSS 39.87%
- Veröffentlicht 08.01.2024 19:15:10
- Zuletzt bearbeitet 18.06.2025 16:15:24
The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files.