The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The CODE MONKEYS PROPOSALS WordPress plugin through version 1.0.1 contains a critical arbitrary file deletion vulnerability that allows any authenticated user—including those with minimal privileges like subscribers—to delete arbitrary files from the web server. This vulnerability exists because the plugin fails to validate file paths before deletion and does not enforce proper capability checks. The impact is severe: attackers can delete essential WordPress configuration files, core system files, or application data, leading to complete site compromise, data loss, or enabling further exploitation. Any organization using this plugin is at risk, particularly those with permissive user registration policies or internal threats from low-privileged accounts.
While this CVE does not map to specific MITRE ATT&CK techniques in the advisory, Casky's 754 mapped security skills would detect the underlying attack patterns associated with this vulnerability. Practitioners using Casky would identify findings related to T1485 (Data Destruction), T1561 (Disk Wipe), and T1529 (System Shutdown/Reboot) patterns, as well as authorization bypass techniques under T1548 (Abuse of Elevation Control Mechanism). Claude's extended reasoning would flag suspicious file deletion operations originating from low-privileged authenticated sessions, path traversal indicators in request logs, and the absence of capability validation checks in plugin code analysis. Security teams would see alerts for repeated DELETE requests targeting sensitive files, failed file access attempts followed by successful deletions, and privilege escalation chains where subscriber accounts perform admin-level file operations.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-77005. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation