← Back to the live CVE advisory feed

CVE-2026-101888: Prime Mover

Severity
8.6 (HIGH)
Vendor
CODEXONICS
Affected versions
0 through before 2.2.1
Fixed version
2.2.1
Patch status
Patched
Published
2026-10-01T17:17:17.453
Modified
2026-10-01T19:17:16.733

Why it matters

This matters because the affected product may be exposed on public websites. A vulnerable plugin can create a direct path to site compromise, malicious code deployment, or data theft.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Check whether the affected WordPress plugin or theme is installed.
  • Update, disable, or remove the affected component if present.
  • Compare installed versions against the affected version range in the advisory.
  • Treat internet-facing systems as higher priority.

Technical summary

The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by computeExtractionParameters() and resumableZipExtractor() in utilities/PrimeMoverSystemCheckUtilities.php to write attacker-controlled content to arbitrary filesystem locations, potentially achieving remote code execution if the written files are interpreted by the web environment.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: OCT 02, 2026 04:00 AM UTC
397 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-101148
BackupSheep WordPress Backup Plugin
Reporter: CONTACT
10
CRITICAL
VIEW RECORD
CVE-2026-55393
Product identification pending
Reporter: MANDIANT-CVE
10
CRITICAL
VIEW RECORD
CVE-2026-79901
BoKS Manager boks-server
Reporter: DF4DEE71-DE3A-4139-9588-11B62FE6C0FF
9.9
CRITICAL
VIEW RECORD
CVE-2026-96658
Product identification pending
Reporter: SECALERT
9.9
CRITICAL
VIEW RECORD
CVE-2026-15989
Super Forms – Drag & Drop Form Builder
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-75957
Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-103752
Authorizer PATCH
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-12627
Fortra's Core Privileged Access Manager (BoKS)
Reporter: DF4DEE71-DE3A-4139-9588-11B62FE6C0FF
9.8
CRITICAL
VIEW RECORD
CVE-2026-56154
Product identification pending
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-57941
Product identification pending
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-59797
Product identification pending
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-104286 EXPLOITED
FortiMail
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-56662
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.6
CRITICAL
VIEW RECORD
CVE-2026-94620
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.4
CRITICAL
VIEW RECORD
CVE-2026-14984
Product identification pending
Reporter: MANDIANT-CVE
9.4
CRITICAL
VIEW RECORD
CVE-2026-55395
Product identification pending
Reporter: MANDIANT-CVE
9.4
CRITICAL
VIEW RECORD
CVE-2026-18397
Product identification pending
Reporter: PSIRT
9.4
CRITICAL
VIEW RECORD
CVE-2026-104480
Product identification pending PATCH
Reporter: 4AC701FE-44E9-4BCD-9585-DD6449257611
9.4
CRITICAL
VIEW RECORD
CVE-2026-76142
Product identification pending
Reporter: VULN
9.3
CRITICAL
VIEW RECORD
CVE-2026-82824
Product identification pending
Reporter: HIRT
9.3
CRITICAL
VIEW RECORD
CVE-2026-82825
Product identification pending
Reporter: HIRT
9.3
CRITICAL
VIEW RECORD
CVE-2026-82827
Product identification pending
Reporter: HIRT
9.3
CRITICAL
VIEW RECORD
CVE-2026-82829
Product identification pending
Reporter: HIRT
9.3
CRITICAL
VIEW RECORD
CVE-2025-41753
Product identification pending
Reporter: INFO
9.3
CRITICAL
VIEW RECORD
CVE-2026-103655
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
9.3
CRITICAL
VIEW RECORD
CVE-2026-103244
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-103264
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-62071
WordPress File Upload PATCH
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-13043
Endpoint Security
Reporter: 5D1C2695-1A31-4499-88AE-E847036FD7E3
9.3
CRITICAL
VIEW RECORD
CVE-2026-103922
capacitor PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-71449
Product identification pending PATCH
Reporter: PRODUCTSECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-103764
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-102628
Product identification pending PATCH
Reporter: 9119A7D8-5EAB-497F-8521-727C672E3725
9.2
CRITICAL
VIEW RECORD
CVE-2026-92966
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-79898
BoKS Manager
Reporter: DF4DEE71-DE3A-4139-9588-11B62FE6C0FF
9.1
CRITICAL
VIEW RECORD
CVE-2026-96659
Product identification pending
Reporter: SECALERT
9.1
CRITICAL
VIEW RECORD
CVE-2026-55083
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-53953
GetSimpleCMS-CE
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-56660
GetSimpleCMS-CE PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-102667
Joyland.ai
Reporter: 9119A7D8-5EAB-497F-8521-727C672E3725
9
CRITICAL
VIEW RECORD
CVE-2026-86345
Red Hat Directory Server 11
Reporter: SECALERT
9
CRITICAL
VIEW RECORD
CVE-2026-101147
Featured Image from URL (FIFU) PATCH
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-80275
1456B Multi-User Gateway
Reporter: DB4DFEE8-A97E-4877-BFAE-EBA6D14A2166
8.8
HIGH
VIEW RECORD
CVE-2026-19807
ByteCoreStack – MCP Connector for AI Tools
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-95687
WPC Shop as a Customer for WooCommerce
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-66246
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-103068
ByteCoreStack – MCP Connector for AI Tools PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-97284
Icegram PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-12405
Product identification pending
Reporter: SECALERT
8.8
HIGH
VIEW RECORD
CVE-2026-93546
Product identification pending
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-104018
Product identification pending PATCH
Reporter: 0BF9931A-6EBF-4F48-BD14-39EE5E1D61F8
8.8
HIGH
VIEW RECORD
CVE-2026-103484
Product identification pending PATCH
Reporter: F86EF6DC-4D3A-42AD-8F28-E6D5547A5007
8.8
HIGH
VIEW RECORD
CVE-2026-70650
GetSimpleCMS-CE
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-104051
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-103765
Product identification pending
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-82826
Product identification pending
Reporter: HIRT
8.7
HIGH
VIEW RECORD
CVE-2026-82828
Product identification pending
Reporter: HIRT
8.7
HIGH
VIEW RECORD
CVE-2026-19253
Cache Enabler PATCH
Reporter: CONTACT
8.7
HIGH
VIEW RECORD
CVE-2026-103262
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-103268
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-103271
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-103272
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2024-58388
Multiple Multifunction Printers
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-102369
Tapo C200 v5
Reporter: F23511DB-6C3E-4E32-A477-6AA17D310630
8.7
HIGH
VIEW RECORD
CVE-2026-104057
podgrab
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-55230
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-54049
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-71542
GetSimpleCMS-CE
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-104020
Product identification pending PATCH
Reporter: FF89BA41-3AA1-4D27-914A-91399E9639E5
8.7
HIGH
VIEW RECORD
CVE-2026-103761
Mooncake
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-89296
Pro Like Button PATCH
Reporter: CONTACT
8.6
HIGH
VIEW RECORD
CVE-2026-64949
Product identification pending
Reporter: SECURITY
8.6
HIGH
VIEW RECORD
CVE-2026-103277
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-103283
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-103292
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-103758
Product identification pending
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-88789
Product identification pending PATCH
Reporter: SECURITY
8.6
HIGH
VIEW RECORD
CVE-2026-95588
AcyMailing SMTP Newsletter PATCH
Reporter: AUDIT
8.6
HIGH
VIEW RECORD
CVE-2026-101888
Prime Mover PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-103766
Product identification pending
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-103259
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-103278
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-103286
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-102379
BuildKit – Product Builder for WooCommerce – Custom PC Builder PATCH
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-103338
Product identification pending
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-102294
TL-WR841N v14
Reporter: F23511DB-6C3E-4E32-A477-6AA17D310630
8.5
HIGH
VIEW RECORD
CVE-2026-55396
Product identification pending
Reporter: MANDIANT-CVE
8.5
HIGH
VIEW RECORD
CVE-2026-76146
Product identification pending
Reporter: VULN
8.4
HIGH
VIEW RECORD
CVE-2026-64950
Product identification pending
Reporter: SECURITY
8.4
HIGH
VIEW RECORD
CVE-2026-73975
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-102514
PeaZip
Reporter: 4DAA8CEA-433A-44BD-9456-53B127FC289A
8.4
HIGH
VIEW RECORD
CVE-2026-103246
Product identification pending PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-103757
Product identification pending
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-101322
Product identification pending PATCH
Reporter: EMO
8.3
HIGH
VIEW RECORD
CVE-2026-103263
Product identification pending PATCH
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD
CVE-2026-94250
Product identification pending PATCH
Reporter: SECURITY
8.2
HIGH
VIEW RECORD
CVE-2026-12540
Product identification pending
Reporter: SECALERT
8.2
HIGH
VIEW RECORD
CVE-2026-12541
Product identification pending
Reporter: SECALERT
8.2
HIGH
VIEW RECORD
CVE-2023-54404
Product identification pending
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD
CVE-2026-96780
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.