Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-85121: Insurify WordPress plugin can be turned off by anyone
CVE-2026-85121 · published today
Summary
The Insurify plugin for WordPress (versions up to 1.0) does not verify who is making certain requests, so anyone on the internet can change key settings. This can cause the whole site to go offline and the plugin to stop working. Remove or update the plugin immediately, and ensure only trusted users have access to administrative functions.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | insurify | <= 1.0 |
Original advisory text
Insurify <= 1.0 - Unauthenticated Arbitrary Option Creation and Overwrite via saveemailtemplatedesign
The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to create and overwrite arbitrary WordPress options with request data, which can take the site offline and deactivate all of its Insurify WordPress plugin through 1.0.
References
- https://wpscan.com/vulnerability/74955313-6f62-4e7c-9b7c-0ab345657377/ exploit vdb-entry technical-description
Severity
9.1
Critical
Type
CWE-862Missing Authorization
Timeline
Published11 Oct 2026
Updated11 Oct 2026
First seen11 Oct 2026
Track software like this
Free during beta