Impact
The Code Monkeys Proposals plugin for WordPress, through version 1.0.1, contains an unchecked file‑deletion endpoint that does not validate the supplied file path or verify the requester’s capability. This flaw allows any authenticated user, such as a subscriber, to craft a path that traverses directories and delete arbitrary files on the server. The resulting loss of site data and configuration can lead to a complete site takeover, enabling an attacker to modify content, upload malware, or disrupt services.
Affected Systems
WordPress installations that have the Code Monkeys Proposals plugin version 1.0.1 or earlier. The vendor is listed as Unknown:CODE MONKEYS PROPOSALS.
Risk and Exploitability
The CVSS score of 9.6 classifies this as a critical vulnerability, while the EPSS score of < 1 % indicates a low current likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. An attacker only needs to be authenticated—no elevated server privileges are required—to delete arbitrary files via the plugin. If exploited, the impact would be total loss of control over the site, as the attacker could modify or delete any file on the server.
OpenCVE Enrichment