CVE-2026-86717: Insurify <= 1.0 - Unauthenticated Arbitrary Option Deletion via removeimg_popup
Published Oct 11, 2026
·Updated
The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to delete arbitrary WordPress options, which can take the site offline and strip every user of their role.
Affected Software
1 affected component
Insurify Insurify WordPress plugin<=1.0
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
Description