Description
The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to create and overwrite arbitrary WordPress options with request data, which can take the site offline and deactivate all of its Insurify WordPress plugin through 1.0.
Published: 2026-10-11
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Availability Impact
Action: Upgrade Plugin
AI Analysis

Impact

Insurify WordPress plugin versions up to 1.0 allow unauthenticated users to trigger a specific AJAX action, 'saveemailtemplatedesign', without proper authorization or nonce checks. Malicious actors can supply arbitrary option names and values, causing the plugin to create new options or overwrite existing ones. This misuse can lead to critical configuration changes that may bring the entire WordPress site offline or deactivate the Insurify plugin, severely impacting service availability.

Affected Systems

The vulnerability affects any WordPress site installed with the Insurify plugin, version 1.0 or earlier. No further vendor or product version details are supplied beyond the plugin name and the version ceiling of 1.0.

Risk and Exploitability

The lack of authentication makes the attack trivial for any person who can send HTTP requests to the site. While no EPSS score is published, the obvious weakness combined with the potential for site downtime assigns a high impact. The attack can be performed remotely by crafting a POST request to the admin‑ajax.php endpoint with the appropriate action and option data. The vulnerability is not listed in CISA KEV at present.

Generated by OpenCVE AI on October 11, 2026 at 07:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a fixed Insurify plugin version that implements proper authorization and nonce checks for the 'saveemailtemplatedesign' action.
  • If no update is currently available, immediately disable the vulnerable AJAX action by removing or disabling the Insurify plugin or by unhooking the 'saveemailtemplatedesign' action.
  • Configure a firewall or security plugin rule to block unauthenticated POST requests to /wp-admin/admin-ajax.php for the 'saveemailtemplatedesign' action until a patch is applied.
  • Review WordPress option tables for unintended values added by the vulnerability and restore the correct configuration.

Generated by OpenCVE AI on October 11, 2026 at 07:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to create and overwrite arbitrary WordPress options with request data, which can take the site offline and deactivate all of its Insurify WordPress plugin through 1.0.
Title Insurify <= 1.0 - Unauthenticated Arbitrary Option Creation and Overwrite via saveemailtemplatedesign
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:44.269Z

Reserved: 2026-09-03T07:58:35.762Z

Link: CVE-2026-85121

cve-icon Vulnrichment

Updated: 2026-10-11T11:23:16.921Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:26.007

Modified: 2026-10-11T12:17:24.223

Link: CVE-2026-85121

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T08:00:13Z

Weaknesses