Skip to main content
Vulnerability Database/CVE-2026-101889

CVE-2026-101889: Prime Mover WordPress Path Traversal

CVE-2026-101889 is a path traversal vulnerability in the Prime Mover WordPress plugin that lets authenticated admins delete arbitrary directories. This article covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-101889 Overview

CVE-2026-101889 is a path traversal vulnerability [CWE-22] in the Prime Mover plugin for WordPress affecting versions before 2.2.1. Authenticated administrators can delete arbitrary directories outside the intended extraction path by importing a crafted WPRIME or TAR package. The flaw resides in how the plugin processes the tar_root_folder value within wprime-config.json. Insufficient path validation in computeExtractVariables() and validateImportedSiteVsPackage() propagates attacker-controlled paths to primeMoverDoDelete(). Successful exploitation can remove critical WordPress directories such as wp-admin, rendering the site inoperable.

Critical Impact

An authenticated administrator can delete arbitrary server directories through a malicious import package, breaking WordPress installations and causing site-wide outages.

Affected Products

  • Prime Mover plugin for WordPress, versions prior to 2.2.1
  • WordPress sites with the plugin installed and administrator-level import privileges enabled
  • Hosting environments where the WordPress process has write and delete permissions on parent directories

Discovery Timeline

  • 2026-10-01 - CVE-2026-101889 published to NVD
  • 2026-10-02 - Last updated in NVD database

Technical Details for CVE-2026-101889

Vulnerability Analysis

The Prime Mover plugin handles site migration by importing WPRIME and TAR packages that contain a wprime-config.json manifest. The manifest defines a tar_root_folder value that the plugin uses to compute extraction and cleanup paths. The plugin trusts this attacker-supplied value during package processing. Because validation does not canonicalize the path or constrain it to the plugin's temporary workspace, traversal sequences and absolute paths are preserved.

When the import workflow completes or fails, primeMoverDoDelete() recursively removes the directory referenced by the computed root folder. An attacker crafting a package with a tar_root_folder such as ../../wp-admin or an absolute path redirects deletion to arbitrary filesystem locations. The result is destruction of WordPress core directories or any writable path accessible to the web server user.

Root Cause

The root cause is improper limitation of a pathname to a restricted directory [CWE-22]. Both computeExtractVariables() and validateImportedSiteVsPackage() consume the tar_root_folder field without normalizing path separators, resolving symbolic components, or verifying the resulting path remains inside the plugin's sanctioned extraction directory.

Attack Vector

Exploitation requires administrator privileges on the target WordPress site, consistent with the CVSS vector requirement for high privileges. The attacker uploads a malicious WPRIME or TAR archive through the Prime Mover import interface. The crafted wprime-config.json contains a tar_root_folder value with directory traversal sequences. After the plugin processes the archive, the deletion routine removes the attacker-selected directory, impacting integrity and availability of the WordPress installation.

For technical details, see the VulnCheck Advisory on Prime Mover.

Detection Methods for CVE-2026-101889

Indicators of Compromise

  • Unexpected absence or truncation of WordPress core directories such as wp-admin, wp-includes, or wp-content/plugins
  • Prime Mover import logs referencing tar_root_folder values containing ../ sequences or absolute paths
  • WPRIME or TAR packages uploaded by administrator accounts shortly before site errors or 500 responses
  • File integrity monitoring alerts for mass deletion events under the WordPress document root

Detection Strategies

  • Inspect the contents of imported wprime-config.json manifests for tar_root_folder values that escape the plugin's temp directory
  • Correlate administrator login events with Prime Mover import actions and subsequent filesystem deletions
  • Monitor PHP error logs for failures referencing missing WordPress core files following plugin import operations
  • Review web server access logs for POST requests to Prime Mover import endpoints from unexpected sources

Monitoring Recommendations

  • Enable file integrity monitoring on wp-admin, wp-includes, and the full WordPress root to flag deletion events
  • Alert on any Prime Mover import executed outside maintenance windows or by accounts without migration duties
  • Centralize WordPress audit logs and web server logs into a SIEM for correlation with filesystem telemetry

How to Mitigate CVE-2026-101889

Immediate Actions Required

  • Upgrade the Prime Mover plugin to version 2.2.1 or later on all WordPress installations
  • Audit administrator accounts and remove unused or stale privileged users with import capabilities
  • Review recent Prime Mover import history and inspect wprime-config.json manifests for traversal payloads
  • Restore any deleted WordPress core directories from backup if signs of exploitation are present

Patch Information

The maintainers addressed the vulnerability in Prime Mover 2.2.1. The fix enforces validation of the tar_root_folder value so that computed extraction and deletion paths remain within the plugin's sanctioned workspace. Refer to the Prime Mover plugin documentation for release notes and update guidance.

Workarounds

  • Disable the Prime Mover plugin until patching is complete if migrations are not actively in progress
  • Restrict administrator access and require multi-factor authentication for all accounts able to import packages
  • Deploy a web application firewall rule that blocks uploads of WPRIME or TAR packages containing ../ in manifest fields
  • Operate WordPress under a least-privilege filesystem user that cannot delete files outside the WordPress document root
bash
# Configuration example: tighten filesystem permissions for the WordPress user
chown -R wp-user:wp-group /var/www/html
find /var/www/html -type d -exec chmod 750 {} \;
find /var/www/html -type f -exec chmod 640 {} \;
# Prevent the web server user from deleting parent directories
chattr +i /var/www/html/wp-admin

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.