OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-86717 (CVSS 9.1)

NVD · officialPublished Oct 11, 2026Risk 50/100EPSS 0.1%

The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to delete arbitrary WordPress options, which can take the site offline and strip every user of their role.

CVSS
9.1
AV:NetworkAC:LowPR:NoneUI:NoneC:NoneI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source