Impact
The vulnerability resides in the Code Monkeys Proposals WordPress plugin up to version 1.0.1. It fails to validate the file path supplied by the user performing a delete request and does not verify the user’s capability to do so. As a result, any authenticated user, including subscribers, can delete any file on the server. This can lead to widespread loss of site assets, compromise of the server, and ultimately a full site takeover. The weakness is a classic case of path traversal and improper input validation.
Affected Systems
WordPress sites running the Code Monkeys Proposals plugin version 1.0.1 or earlier. The plugin is listed as Unknown:CODE MONKEYS PROPOSALS in vendor data. No additional version detail is provided beyond the 1.0.1 upper bound.
Risk and Exploitability
Enterprise and small‑site WordPress installations are at risk if the vulnerable plugin is present. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, so while the exploitation probability is undetermined, the potential damage is significant. Attackers would provide a crafted file path via the delete endpoint, bypassing permission checks; the admin or hosting environment must be prepared for a potential site compromise.
OpenCVE Enrichment