CVE-2026-77005 PUBLISHED

Code Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal

Assigner: WPScan
Reserved: 20.08.2026 Published: 12.09.2026 Updated: 12.09.2026

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.

Product Status

Vendor Unknown
Product CODE MONKEYS PROPOSALS
Versions Default: unknown
  • affected from 0 to 1.0.1 (incl.)

Credits

  • João Ramos Maciel finder
  • WPScan coordinator

References

Problem Types

  • CWE-73 External Control of File Name or Path CWE