CyberRota Analysis
AI-GeneratedThe CODE MONKEYS PROPOSALS WordPress plugin versions up to 1.0.1 is vulnerable due to inadequate validation of user-supplied file paths and lack of user capability checks, enabling any authenticated user to delete arbitrary files on the server. This flaw poses a significant risk, as it could lead to complete site takeover. WordPress site administrators and users of this plugin should prioritize immediate updates to mitigate potential exploitation.
Original NVD Description
The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.