Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-86717: Insurify plugin lets anyone delete site settings
CVE-2026-86717 · published today
Summary
The Insurify WordPress plugin (versions up to 1.0) allows anyone on the internet to trigger a request that removes important site settings. This can shut the website down and strip all users of their roles. Update the plugin to a secured version or disable it until the issue is fixed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | insurify | <= 1.0 |
Original advisory text
Insurify <= 1.0 - Unauthenticated Arbitrary Option Deletion via removeimg_popup
The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to delete arbitrary WordPress options, which can take the site offline and strip every user of their role.
References
- https://wpscan.com/vulnerability/598c7ff4-d6cb-4b4b-a8cd-83f019d10350/ exploit vdb-entry technical-description
Severity
9.1
Critical
Type
CWE-862Missing Authorization
Timeline
Published11 Oct 2026
Updated11 Oct 2026
First seen11 Oct 2026
Track software like this
Free during beta