CRITICAL
9.1 CVE-2026-86717 Published 11 Oct 2026
Insurify WordPress Plugin Missing Authorization Lets Unauthenticated Users Delete Options
Worried this affects your website?
The Insurify WordPress plugin through version 1.0 contains a missing authorization and nonce check vulnerability in one of its AJAX actions.
Because the action lacks both authorization and nonce validation, unauthenticated users can exploit it to delete arbitrary WordPress options.
- Affected versions: through 1.0
- Impact: can take the site offline and strip every user of their role
Reference: CVE-2026-86717 on NVD
← Back to Security News