CVE-2026-85121
Received Received - Intake

Unauthenticated Option Update in Insurify WordPress Plugin

Vulnerability report for CVE-2026-85121, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to create and overwrite arbitrary WordPress options with request data, which can take the site offline and deactivate all of its Insurify WordPress plugin through 1.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Insurify 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Insurify WordPress plugin version 1.0 or below has a vulnerability where unauthenticated users can exploit an AJAX action called saveemailtemplatedesign to create and overwrite arbitrary WordPress options. This happens because the plugin lacks proper authorization and nonce checks, allowing attackers to manipulate site settings.

Detection Guidance

Check for unauthorized modifications to WordPress options via the Insurify plugin's AJAX action. Monitor network traffic for POST requests to /wp-admin/admin-ajax.php with the action parameter set to saveemailtemplatedesign. Review server logs for suspicious activity targeting this endpoint.

Impact Analysis

This vulnerability can allow attackers to take your website offline or deactivate all plugins by changing critical site settings. Since it requires no authentication, anyone can exploit it, potentially causing significant disruption to your WordPress site.

Compliance Impact

This vulnerability could lead to unauthorized modifications of WordPress site settings, potentially disabling security features or altering data handling configurations. Such changes may violate compliance requirements under GDPR or HIPAA by exposing sensitive data or disrupting access controls.

Mitigation Strategies

Immediately disable the Insurify WordPress plugin if installed. Restrict access to the admin-ajax.php file via server configuration. Update firewall rules to block requests containing the saveemailtemplatedesign action. Monitor site settings for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85121. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart