Vulnary
← back to the feed
Critical· 9.6

CVE-2026-77005

This critical vulnerability (CVE-2026-77005) affects the CODE MONKEYS WordPress plugin (version 1.0.1 and earlier) because it fails to validate user-supplied file paths before deletion and does not properly verify user permissions. Any authenticated user—including low-privilege accounts like subscribers—can exploit this flaw to delete arbitrary files on the server, potentially resulting in full site compromise.

publishedSep 12, 2026
last modifiedSep 12, 2026
sourcesNVD
severity · cvss
9.6
critical · how bad it is
exploitation · epss
<1%
4th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Oct 27, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

CODE MONKEYS WordPress plugin (v1.0.1 and earlier)

02

Real-world impact

An attacker could destroy critical site files, leading to loss of control over the website and potential further exploitation.

03

Why this severity

The CVSS score of 9.6 (Critical) indicates this is a high-severity issue that can be exploited without user interaction and may allow complete system takeover.

04

What to do about it

no official fix yet
interim mitigations
  • Upgrade the CODE MONKEYS WordPress plugin to a newer version that addresses this issue (if a fix becomes available).
  • Restrict file deletion operations to authorized users only via proper access controls.
  • Implement strict path validation and authorization checks on the server side.

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No official fix is documented in the provided sources. The vulnerability details come from the NVD entry for CVE-2026-77005, which describes the missing file path validation and insufficient permission checks in the CODE MONKEYS plugin.

05

Timeline

06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredLow
User interactionNone needed
ScopeChanged
Confidentiality impactNone
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
CVE-2026-77005: This critical vulnerability (CVE-2026-77005) affects the CODE MONKEYS · Vulnary