WordPress security by component
CODE MONKEYS PROPOSALS
CODE MONKEYS PROPOSALS (code-monkeys-proposals) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 9.6.
Plugin slug:
code-monkeys-proposalsLatest vulnerability
CVE-2026-77005: CODE MONKEYS PROPOSALS lets subscribers delete arbitrary files
CODE MONKEYS PROPOSALS through 1.0.1 deletes a caller-supplied file path without validating it or checking the caller's capability. Any authenticated user, including a subscriber, can delete arbitrary server files and potentially take over the site. The authoritative export does not name the action, path parameter, or deletion function.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-77005
CODE MONKEYS PROPOSALS lets subscribers delete arbitrary files
CODE MONKEYS PROPOSALS through 1.0.1 deletes a caller-supplied file path without validating it or checking the caller's capability. Any authenticated user, including a subscriber, can delete arbitrary server files and potentially take over the site. The authoritative export does not name the action, path parameter, or deletion function.
|
See mitigation notes |
CVE9.6
NVDPending
|