CVE-2026-77005
Received Received - Intake

Unauthenticated File Deletion in Code Monkeys Proposals WordPress Plugin

Vulnerability report for CVE-2026-77005, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-12

Last updated on: 2026-09-12

Assigner: WPScan

Description

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-12
Last Modified
2026-09-12
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
code_monkeys proposals to 1.0.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in the Code Monkeys Proposals WordPress plugin allows any authenticated user, even with minimal privileges like a subscriber, to delete arbitrary files on the server. This happens because the plugin does not validate file paths before deletion and fails to check user capabilities.

Detection Guidance

To detect this vulnerability, check if the 'Code Monkeys Proposals' WordPress plugin version 1.0.1 or earlier is installed. Inspect server logs for unusual file deletion requests or unauthorized file access patterns.

Impact Analysis

This vulnerability can lead to a complete site takeover. Attackers could delete critical files, disrupting website functionality or gaining unauthorized access to sensitive data.

Compliance Impact

This vulnerability could lead to unauthorized file deletion, potentially exposing sensitive data stored on the server. If exploited, it may result in violations of GDPR (General Data Protection Regulation) due to unauthorized access or loss of personal data, and HIPAA (Health Insurance Portability and Accountability Act) if protected health information is compromised. Unauthorized file deletion could also disrupt compliance with data integrity requirements.

Mitigation Strategies

Immediately update the 'Code Monkeys Proposals' plugin to the latest version. If no update is available, consider disabling or removing the plugin until a patch is released. Review user roles and permissions to ensure only trusted users have administrative access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77005. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart