CVE-2026-86717
Received Received - Intake

Unauthenticated Option Deletion in Insurify WordPress Plugin

Vulnerability report for CVE-2026-86717, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to delete arbitrary WordPress options, which can take the site offline and strip every user of their role.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Insurify 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Insurify WordPress plugin version 1.0 or below has a flaw where an AJAX action lacks proper authorization and nonce checks. This allows unauthenticated users to delete arbitrary WordPress options, potentially taking the site offline and removing all user roles.

Detection Guidance

Check if the Insurify WordPress plugin version 1.0 or below is installed. Look for unauthorized deletion of WordPress options or sudden loss of user roles. Monitor AJAX requests to identify suspicious activity targeting the vulnerable endpoint.

Impact Analysis

This vulnerability can cause your website to go offline and strip all users of their roles, effectively disabling access to the site. It may also lead to data loss or unauthorized modifications.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by allowing unauthorized access to modify or delete critical site configurations and user roles, potentially exposing sensitive data or disrupting access controls.

Mitigation Strategies

Immediately update the Insurify plugin to the latest version if an update is available. If no update exists, consider disabling or removing the plugin until a patch is released. Implement additional access controls and monitor for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86717. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart