CRITICAL
9.1 CVE-2026-85121 Published 11 Oct 2026
Insurify WordPress Plugin Arbitrary Option Overwrite Vulnerability
Worried this affects your website?
The Insurify WordPress plugin through version 1.0 contains a missing authorization and nonce check vulnerability in one of its AJAX actions.
Because the action lacks both authorization and nonce validation, unauthenticated users can create or overwrite arbitrary WordPress options using request data.
- Affected versions: Insurify WordPress plugin through 1.0
- Impact: An attacker can take the site offline and deactivate the Insurify plugin.
Reference: CVE-2026-85121 on NVD
← Back to Security News