Impact
The Insurify WordPress plugin in versions through 1.0 suffers from a missing authorization and nonce verification on its AJAX action triggered by the removeimg_popup endpoint. Because the backend function that deletes WordPress options does not restrict who may call it, an unauthenticated visitor can instruct the plugin to delete arbitrary options stored by the site. The deletion of critical options can render the site completely non‑functional and can also erase all user roles, effectively taking the website offline and removing all administrative privileges from legitimate users.
Affected Systems
The vulnerability affects the Insurify WordPress plugin version 1.0 and any earlier releases. No separate vendor or product name beyond the Insurify plugin was listed, meaning all WordPress installations that relied on this plugin and have not updated past 1.0 are potentially impacted.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the lack of authentication combined with the ability to erase critical options suggests a high risk to site integrity and availability. The attack vector is purely unauthenticated and requires only that the target WordPress site hosts the vulnerable plugin, making exploitation relatively straightforward for a determined attacker.
OpenCVE Enrichment