Prime Mover – Backup and Migration に脆弱性 — CVE-2026-101888
いま何をすべきか
Prime Mover – Backup and Migration を 2.2.1 以降に更新してください。
影響を受けるバージョン
- 2.2.1 未満のすべて
対象: プラグイン「Prime Mover – Backup and Migration」(prime-mover)
何が起きるのか
The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by computeExtractionParameters() and resumableZipExtractor() in utilities/PrimeMoverSystemCheckUtilities.php to write attacker-controlled content to arbitrary filesystem locations, potentially achieving remote code execution if the written files are interpreted by the web environment.
ここから先の選択肢
1. 自分たちで対応する
更新の手順、バックアップの取り方、壊れたときの戻し方をまとめています。
2. いまの制作会社・保守業者に頼む
Prime Mover – Backup and Migration を使っているかどうかを含めて確認を依頼してください。 無料診断を実行すると、そのまま渡せる依頼文を作れます。
3. 相談先がない・自分では難しい
連絡が取れる相手がいない、管理画面に入れない、侵入された疑いがある。 そうした場合はご相談ください。