CVE-2026-85121: Insurify <= 1.0 - Unauthenticated Arbitrary Option Creation and Overwrite via saveemailtemplatedesign
Published Oct 11, 2026
·Updated
The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to create and overwrite arbitrary WordPress options with request data, which can take the site offline and deactivate all of its Insurify WordPress plugin through 1.0.
Affected Software
1 affected component
Insurify Insurify WordPress plugin<=1.0
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness