CriticalCritical vulnerability
CVE-2026-86717 (CVSS 9.1)
NVD · officialPublished Oct 11, 2026Risk 50/100EPSS 0.1%
The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to delete arbitrary WordPress options, which can take the site offline and strip every user of their role.
Technical details
CVSS
9.1
AV:NetworkAC:LowPR:NoneUI:NoneC:NoneI:HighA:High
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source