→ برگشت به فید آسیبپذیریها
CVE-2026-101889 · prime-mover
پیمایش دایرکتوری (Directory Traversal) در افزونه Prime Mover
The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation in computeExtractVariables() and validateImportedSiteVsPackage() to cause primeMoverDoDelete() to remove directories outside the intended extraction path, potentially deleting critical WordPress directories such as wp-admin and rendering the site inoperable.
نسخههای تحت تأثیر
<= 2.2.1
راهنمای اقدام و رفع مشکل (Remediation)
- ۱. پشتیبانگیری: قبل از اعمال هرگونه تغییر، یک بکاپ کامل از پایگاه داده و فایلهای سایت تهیه کنید.
- ۲. بهروزرسانی سریع: افزونه یا هسته prime-mover را بلافاصله به آخرین نسخه ارائهشده ارتقا دهید.
- ۳. فایروال و مانیتورینگ: در صورت عدم امکان آپدیت فوری، رولهای امنیتی WAF را فعال کرده و لاگهای وبسرور را پایش نمایید.
مراجع رسمی و مستندات
- https://wordpress.org/plugins/prime-mover/#developers ↗
- https://www.vulncheck.com/advisories/prime-mover-path-traversal-via-wprime-config-json ↗
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1b9bebab-e0e4-4f54-b297-aec0dcecf13e?source=api-prod ↗
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1b9bebab-e0e4-4f54-b297-aec0dcecf13e ↗