Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-86717: Insurify plugin lets anyone delete site settings

CVE-2026-86717 · published today
Summary

The Insurify WordPress plugin (versions up to 1.0) allows anyone on the internet to trigger a request that removes important site settings. This can shut the website down and strip all users of their roles. Update the plugin to a secured version or disable it until the issue is fixed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
unknown insurify <= 1.0
Original advisory text
Insurify <= 1.0 - Unauthenticated Arbitrary Option Deletion via removeimg_popup
The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to delete arbitrary WordPress options, which can take the site offline and strip every user of their role.
References
Severity
9.1 Critical
Type
CWE-862Missing Authorization
Timeline
Published11 Oct 2026
Updated11 Oct 2026
First seen11 Oct 2026
Sources
CVE-2026-86717 · MITRE
Track software like this
Free during beta