CVE-2026-101888 Overview
CVE-2026-101888 is a Zip Slip path traversal vulnerability in the Prime Mover plugin for WordPress [CWE-22]. The flaw affects all versions before 2.2.1 and resides in the ZIP import routine used for site migrations. Authenticated administrators can craft ZIP archives containing entries with traversal sequences, causing the plugin to write arbitrary files outside the intended extraction directory. The vulnerable logic lives in computeExtractionParameters() and resumableZipExtractor() within utilities/PrimeMoverSystemCheckUtilities.php. Successful exploitation can lead to remote code execution when written files are interpreted by the PHP runtime.
Critical Impact
An authenticated administrator can achieve arbitrary file write and potential remote code execution on the underlying WordPress host.
Affected Products
- Prime Mover plugin for WordPress, versions prior to 2.2.1
- WordPress sites using Prime Mover for migration ZIP import
- Any PHP-interpreted web environment hosting the vulnerable plugin
Discovery Timeline
- 2026-10-01 - CVE-2026-101888 published to NVD
- 2026-10-02 - Last updated in NVD database
Technical Details for CVE-2026-101888
Vulnerability Analysis
The Prime Mover plugin provides WordPress site migration by exporting and importing ZIP archives containing site data and files. During import, the plugin extracts archive entries to a working directory, but it does not validate that resolved entry paths remain within that directory. An attacker who can upload a crafted migration ZIP can include entries whose names contain ../ sequences, causing extraction to resolve outside the intended target. The result is attacker-controlled file content written to arbitrary filesystem locations accessible to the web server process.
Root Cause
The root cause is missing canonicalization and containment checks on ZIP entry names in computeExtractionParameters() and resumableZipExtractor() inside utilities/PrimeMoverSystemCheckUtilities.php. The extractor concatenates the destination directory with the entry name without verifying the resolved path remains a child of the extraction root. This is the classic Zip Slip pattern catalogued under CWE-22.
Attack Vector
Exploitation requires administrator-level WordPress credentials and network access to the import workflow. An attacker uploads a malicious migration archive through the Prime Mover import interface. The plugin processes the archive and writes file contents to attacker-chosen locations, including directories served by the web environment. Dropping a PHP file into a web-accessible path yields remote code execution under the web server user. See the VulnCheck advisory on Prime Mover for further detail.
No verified public proof-of-concept code is available at the time of writing. The vulnerability mechanism follows the standard Zip Slip pattern: a ZIP entry named with traversal segments is written through an unchecked path join, placing attacker-controlled bytes outside the intended extraction root.
Detection Methods for CVE-2026-101888
Indicators of Compromise
- Unexpected PHP or executable files appearing under wp-content/, wp-includes/, or the web root with recent modification timestamps.
- Prime Mover import jobs initiated by administrator accounts outside of planned migration windows.
- ZIP archives in Prime Mover working directories containing entry names with ../ sequences or absolute paths.
- Web server access logs showing requests to newly created .php files immediately after an import operation.
Detection Strategies
- Inspect uploaded migration archives for entries whose normalized paths escape the extraction root before processing.
- Monitor filesystem writes by the PHP-FPM or Apache user to directories outside wp-content/uploads/prime-mover-export-files/.
- Correlate WordPress admin audit logs with filesystem change events to identify imports followed by anomalous file creation.
Monitoring Recommendations
- Enable file integrity monitoring across the WordPress document root and plugin directories.
- Alert on creation of PHP files outside expected paths such as plugin and theme directories.
- Log and review all Prime Mover import actions, including the administrator account, source IP, and archive filename.
How to Mitigate CVE-2026-101888
Immediate Actions Required
- Upgrade the Prime Mover plugin to version 2.2.1 or later on every WordPress instance.
- Audit administrator accounts and revoke credentials that are not required for operational use.
- Review the web root and plugin directories for unexpected files created since the plugin was installed.
- Rotate secrets stored on affected hosts, including database credentials and API keys, if arbitrary write is suspected.
Patch Information
Upgrade Prime Mover to version 2.2.1 or later, which adds path containment checks during ZIP extraction. Refer to the Prime Mover plugin page for release details and the VulnCheck advisory for vulnerability specifics.
Workarounds
- Disable or uninstall the Prime Mover plugin until the upgrade can be applied.
- Restrict administrator access to the WordPress site to trusted operators and enforce multi-factor authentication.
- Use web server configuration to deny PHP execution in directories that should only contain static assets, such as wp-content/uploads/.
- Place the WordPress admin interface behind an IP allowlist or VPN during the exposure window.
# Example: deny PHP execution in uploads directory (Apache)
<Directory "/var/www/html/wp-content/uploads">
<FilesMatch "\.(php|phtml|phar)$">
Require all denied
</FilesMatch>
</Directory>
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.