CVE-2026-101888

CVE-2026-101888 published: The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft Z...

View full NVD advisory → ← Back to CVE watch