CVE-2026-77005: Code Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal
The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
Any authenticated WordPress user can exploit it, including users with only the Subscriber role. The vulnerable deletion request does not verify the requesting user's capability.
What must an attacker provide to delete files?
The attacker needs an authenticated account and must submit a user-controlled file path to the vulnerable deletion functionality. The plugin does not validate that path before deleting the referenced file.
Are sites running version 1.0.1 affected?
Yes. The affected versions are through 1.0.1, which includes version 1.0.1.