Impact
Insurify WordPress plugin versions up to 1.0 allow unauthenticated users to trigger a specific AJAX action, 'saveemailtemplatedesign', without proper authorization or nonce checks. Malicious actors can supply arbitrary option names and values, causing the plugin to create new options or overwrite existing ones. This misuse can lead to critical configuration changes that may bring the entire WordPress site offline or deactivate the Insurify plugin, severely impacting service availability.
Affected Systems
The vulnerability affects any WordPress site installed with the Insurify plugin, version 1.0 or earlier. No further vendor or product version details are supplied beyond the plugin name and the version ceiling of 1.0.
Risk and Exploitability
The lack of authentication makes the attack trivial for any person who can send HTTP requests to the site. While no EPSS score is published, the obvious weakness combined with the potential for site downtime assigns a high impact. The attack can be performed remotely by crafting a POST request to the admin‑ajax.php endpoint with the appropriate action and option data. The vulnerability is not listed in CISA KEV at present.
OpenCVE Enrichment