External risk intelligence

CODE MONKEYS PROPOSALS WordPress Plugin Arbitrary File Deletion Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-77005

The vulnerability exists in a WordPress plugin. WordPress installations are commonly deployed as internet-facing web applications, making the plugin's functionality and its associated attack surface reachable from the public internet in standard deployment patterns.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects a WordPress plugin, allowing any authenticated user to delete arbitrary files on the server. This could potentially lead to a complete takeover of the website.

  • Any user can delete server files.
  • Confirms the need for diligent plugin management.
  • Ensure plugins are reviewed for security risks.

Attack Path

How an attacker could exploit the issue

An attacker with basic user access to a WordPress site can delete any file on the server. This is possible because the vulnerable plugin does not properly check user permissions or sanitize file paths before performing deletions. Successful exploitation can result in a complete takeover of the website.

  • Any authenticated user can access.
  • Deleting arbitrary files.
  • Leads to site takeover.

Live Threat

Current exploitation, exposure, and threat context

An authenticated user could delete arbitrary files on the server when the CODE MONKEYS PROPOSALS WordPress plugin is installed and active. This is because the plugin does not properly validate file paths before deletion and does not check user permissions.

  • Arbitrary files on the server.
  • Deleting files without proper validation.
  • Potential site takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in a WordPress plugin affects any authenticated user and can lead to arbitrary file deletion and potential site takeover. The first practical step is for the application owner to identify all WordPress instances, confirm exposure and criticality, and then plan remediation.

  • Application owners should own this issue.
  • Verify WordPress plugin reachability and criticality.
  • Plan remediation considering site impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the CODE MONKEYS PROPOSALS plugin?

CODE MONKEYS PROPOSALS is a software component designed for WordPress sites to manage and organize proposals. Like many WordPress plugins, it extends the core functionality of a website, in this case handling document workflows. Because it runs within the WordPress ecosystem, it relies on the host environment's file system, which this vulnerability puts at risk.

What does CWE-73 mean for CVE-2026-77005?

This vulnerability is classified as CWE-73, or Improper Neutralization of Input During Pathname Resolution. In plain English, the plugin accepts a file path from a user but fails to verify that the path is safe or authorized. Because it does not check if the user is allowed to modify these files, it incorrectly assumes any requested deletion is legitimate, allowing unauthorized access to the server's file system.

How can an attacker trigger this vulnerability?

An attacker needs a valid user account on the WordPress site, even one with low-level permissions like a subscriber. The bug is triggered when that user sends a specific request to the plugin that specifies a file path to delete. It is important to note that the vulnerability is not triggered by public visitors who lack an account, as the flaw relies on the plugin's failure to enforce access controls during the request.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal indicates the vulnerability is 'Likely' to be reachable because WordPress sites are typically deployed as internet-facing applications. Since the plugin's functionality is exposed through the web interface, any authenticated user—including those who register on your site—can interact with the vulnerable code from the public internet.

What should I do if I use this plugin?

Your first step is to locate all instances of the CODE MONKEYS PROPOSALS plugin within your WordPress environment to determine where it is active. Once you have identified the affected sites, prioritize restricting user registration or disabling the plugin until you can confirm a secure path forward. Reviewing your plugin list for similar tools is also a good practice to manage your overall site risk.

References