Description
The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to delete arbitrary WordPress options, which can take the site offline and strip every user of their role.
Published: 2026-10-11
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation and Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The Insurify WordPress plugin in versions through 1.0 suffers from a missing authorization and nonce verification on its AJAX action triggered by the removeimg_popup endpoint. Because the backend function that deletes WordPress options does not restrict who may call it, an unauthenticated visitor can instruct the plugin to delete arbitrary options stored by the site. The deletion of critical options can render the site completely non‑functional and can also erase all user roles, effectively taking the website offline and removing all administrative privileges from legitimate users.

Affected Systems

The vulnerability affects the Insurify WordPress plugin version 1.0 and any earlier releases. No separate vendor or product name beyond the Insurify plugin was listed, meaning all WordPress installations that relied on this plugin and have not updated past 1.0 are potentially impacted.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the lack of authentication combined with the ability to erase critical options suggests a high risk to site integrity and availability. The attack vector is purely unauthenticated and requires only that the target WordPress site hosts the vulnerable plugin, making exploitation relatively straightforward for a determined attacker.

Generated by OpenCVE AI on October 11, 2026 at 07:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Insurify WordPress plugin to a version newer than 1.0 where the unauthorized option deletion issue has been fixed.
  • If an update is unavailable, remove or disable the Insurify plugin to eliminate the vulnerable AJAX endpoint.
  • Configure a web application firewall or security plugin to block unauthenticated requests to the removeimg_popup AJAX action as a temporary mitigation.

Generated by OpenCVE AI on October 11, 2026 at 07:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to delete arbitrary WordPress options, which can take the site offline and strip every user of their role.
Title Insurify <= 1.0 - Unauthenticated Arbitrary Option Deletion via removeimg_popup
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:43.879Z

Reserved: 2026-09-08T11:23:25.473Z

Link: CVE-2026-86717

cve-icon Vulnrichment

Updated: 2026-10-11T11:22:33.515Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:26.337

Modified: 2026-10-11T12:17:24.653

Link: CVE-2026-86717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T08:00:13Z

Weaknesses