CVE-2026-101890

CVE-2026-101890 published: The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a...

View full NVD advisory → ← Back to CVE watch