CRITICAL 9.6 CVE-2026-77005 Published 12 Sept 2026

WordPress CODE MONKEYS PROPOSALS Plugin Arbitrary File Deletion

Worried this affects one of your servers?

The CODE MONKEYS PROPOSALS WordPress plugin, up to version 1.0.1, has a critical security vulnerability.

It does not validate user-supplied file paths before deleting files and does not check the user's capabilities, allowing any authenticated user, including subscribers, to delete arbitrary files on the server.

This can lead to a site takeover.

Reference: CVE-2026-77005 on NVD

← Back to Security News