🔐 CVE Alert

CVE-2026-77005

CRITICAL 9.6

Code Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal

CVSS Score
9.6
EPSS Score
0.0%
EPSS Percentile
0th

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.

Vendor unknown
Product code monkeys proposals
Published Sep 12, 2026
Last Updated Sep 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown code monkeys proposals

Be the first to know when new critical vulnerabilities affecting unknown code monkeys proposals are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / CODE MONKEYS PROPOSALS
0 ≤ 1.0.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/b9340774-84c2-41ec-a770-0123dd5608c2/

Credits

João Ramos Maciel WPScan