SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-77005

CRITICAL · CVSS 9.6 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The CODE MONKEYS PROPOSALS WordPress plugin versions up to 1.0.1 is vulnerable due to inadequate validation of user-supplied file paths and lack of user capability checks, enabling any authenticated user to delete arbitrary files on the server. This flaw poses a significant risk, as it could lead to complete site takeover. WordPress site administrators and users of this plugin should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-77005
Severity
CRITICAL
CVSS
9.6
EPSS
0.30%
WordPress

Original NVD Description

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.