CVE-2026-101889 | Codexonics Prime Mover Plugin up to 2.2.0 Path Validation wprime-config.json tar_root_folder path traversal

SecurityVulns

A vulnerability, which was classified as problematic, has been found in Codexonics Prime Mover Plugin up to 2.2.0. Affected by this issue is the function computeExtractVariables/validateImportedSiteVsPackage of the file wprime-config.json of the component Path Validation. The manipulation of the argument tar_root_folder leads to path traversal.

This vulnerability is documented as CVE-2026-101889. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More