The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory so that the malicious value renders unescaped in the column_site_title() method of PrimeMoverBackupMenuListTable.php, triggering script execution in an administrator's browser when they view the Prime Mover Packages list table without needing to restore the package.

Project Subscriptions

Vendors Products
Codexonics Subscribe
Prime Mover Subscribe
Wordpress-extensions Subscribe
Prime Mover Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions prime Mover
Vendors & Products Wordpress-extensions
Wordpress-extensions prime Mover

Thu, 01 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Codexonics
Codexonics prime Mover
CPEs cpe:2.3:a:codexonics:prime_mover:*:*:*:*:*:wordpress:*:*
Vendors & Products Codexonics
Codexonics prime Mover

Thu, 01 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory so that the malicious value renders unescaped in the column_site_title() method of PrimeMoverBackupMenuListTable.php, triggering script execution in an administrator's browser when they view the Prime Mover Packages list table without needing to restore the package.
Title Prime Mover < 2.2.1 Stored XSS via Package Metadata
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T21:44:58.019Z

Reserved: 2026-09-28T15:44:45.390Z

Link: CVE-2026-101890

cve-icon Vulnrichment

Updated: 2026-10-01T18:07:46.107Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T17:17:17.767

Modified: 2026-10-02T18:00:34.733

Link: CVE-2026-101890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:50:03Z

Weaknesses