← WordPress Vulnerabilities
WordPress security by component

CODE MONKEYS PROPOSALS

CODE MONKEYS PROPOSALS (code-monkeys-proposals) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 9.6.

Plugin slug: code-monkeys-proposals

CVE-2026-77005: CODE MONKEYS PROPOSALS lets subscribers delete arbitrary files

CODE MONKEYS PROPOSALS through 1.0.1 deletes a caller-supplied file path without validating it or checking the caller's capability. Any authenticated user, including a subscriber, can delete arbitrary server files and potentially take over the site. The authoritative export does not name the action, path parameter, or deletion function.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for code-monkeys-proposals
Safe version
Sep 12, 2026 CVE-2026-77005
CODE MONKEYS PROPOSALS lets subscribers delete arbitrary files
CODE MONKEYS PROPOSALS through 1.0.1 deletes a caller-supplied file path without validating it or checking the caller's capability. Any authenticated user, including a subscriber, can delete arbitrary server files and potentially take over the site. The authoritative export does not name the action, path parameter, or deletion function.
See mitigation notes
CVE9.6
NVDPending